Advertisement
Promo

Security threats Toolkit

Antivirus holes zipped up

Munir Kotadia ZDNet Australia

Published: 20 Oct 2004 09:30 BST

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

Sophos updated its antivirus engine on Wednesday to plug a security hole that allowed virus writers to manipulate compressed files and avoid detection by the antivirus software's scans.

The vulnerability was discovered by US-based security firm iDEFENSE and also affected products from McAfee, Computer Associates, Kaspersky, Eset and RAV.

Sophos admitted the vulnerability existed on Tuesday after being contacted by ZDNet UK sister site ZDNet Australia. A spokesperson for the company said vulnerable products will automatically update today and a fix will be available for download from the company's Web site on Friday.

However, Sophos played down the seriousness of the problem, claiming that there was a "theoretical risk" and the company had not seen any examples of the vulnerability being exploited.

"Sophos has enhanced its scan engine (Version 3.87.0) to deal with malformed ZIP files. Sophos has not seen any examples of malware attempting to employ this vulnerability. Furthermore, the vulnerability does not prevent Sophos's desktop on-access scanner from correctly detecting viruses that manage to bypass the email gateway software," the spokesperson said.

Symantec on Wednesday hit back at claims by Secunia, a European security Web site, that hackers can turn off the auto protect feature on some of Symantec's consumer antivirus and Internet security applications.

According to Secunia, some versions of Norton AntiVirus contain errors that could allow malicious users to disable the product's auto-protect feature.

The Secunia advisory said vulnerable versions of the software could "be exploited by an unprivileged user to force the auto-protection to be disabled… It can further be exploited to download and execute malicious files that normally would be caught by the antivirus program." But Symantec told ZDNet UK sister site ZDNet Australia that when the auto-protect function is disabled – by terminating the CCApp.exe process – Norton AntiVirus’s auto-protect feature is still active.

"The termination of the CCApp.exe process does not result in Norton AntiVirus’s Auto-Protect function being disabled. While terminating CCApp.exe will cause the disappearance of the Norton AntiVirus icon in the system tray, and will disable notification of Auto-Protect, the user’s system is still protected," the Symantec spokesperson said.

Neil Campbell, the national security manager of IT services company Dimension Data, told ZDNet Australia he was not surprised that the antivirus vendors are playing down the risks while the researchers that discover the vulnerabilities play them up.

"One of the ways to gain credibility as a security researcher is by identifying vulnerabilities. It is in the researcher’s best interests to talk potential problems up. The vendors naturally have to talk the problem down and somewhere in-between there is the truth," said Campbell.

Campbell said a good way of deciding on the actual severity is to look at the number of people being affected and the impact the flaw is having.

"If you can’t identify any victims then you would tend to believe the vendors. But if you know that five million computers have been attacked you would tend to believe the security researchers," said Campbell.

  • Email
  • Trackback
  • Clip Link
  • Print friendlyPrint with EPSON

Did you find this article useful?
70 out of 108 people found this useful


Full Talkback thread

0 comments

Company/Topic Alerts

Create a new alert from the list below:






Video icon

Video

Sentry Posts Blog

INIFiles: Getting those legacy files i...

Handling INI files can be a little tricky these days when you have to consider new security restrictions, virtualized environment restrictions (App-V and Citrix) and legacy applications... More

Post a comment

Motorola Droid Drops Today: Happy Droi...

Motorola Droid Drops Today: Happy Droid Day America! Author: Eric Everson, Mobile Security Expert If you’re wondering what all of the buzz is about with words like Droid and Android... More

Post a comment

Mobile Security Profile: BlackBerry St...

Mobile Security Profile: BlackBerry Storm2 Author: Eric Everson BlackBerry handsets are a staple of office culture; from syncing calendars to sharing business-related data,... More

Post a comment


Skip Sub Navigation Links to CNET Brand Links

Help

Become part of the ZDNet community.

Newsletters