ZDNet UK


Skip to Main Content

ZDNet.co.uk - Winner of Best Business Website 2007
  1. Home
  2. News
  3. Blogs
  4. Reviews
  5. Prices
  6. Resources
  7. Community
  8. My ZDNet

 

ZDNet UK RSS Feeds


IT Jobs

Security threats Toolkit

Symantec flaw putting users at risk

Published: 10 Feb 2005 09:30 GMT

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

Symantec has issued a patch for a flaw in its scanning software that could cause a virus to execute, rather than catch it.

The vulnerability affects an antivirus library used by the majority of Symantec's antivirus and anti-spam products, including Norton SystemWorks 2004 and Symantec Mail Security for Exchange, the security provider said on Tuesday.

The software is aimed at a range of systems, from consumer desktops to large corporate mail servers, meaning the flaw could be used to take control of key corporate systems or to install programs to grab people's identity data.

"The impact of this vulnerability is exaggerated by the fact that many email and other traffic routing gateways make use of file-scanning utilities that make use of the vulnerable library," Symantec said in an advisory. "This could allow an attacker to potentially exploit high-profile systems used to filter malicious data, and potentially allow further compromise of targeted internal networks."

Computers are at risk if they run an unpatched version of a Symantec product that scans files to detect malicious code and if they use the Microsoft Windows, Mac OS X, Linux, Solaris and AIX operating systems, Symantec said.

But the flaw does not affect the latest versions of some of the products, such as Norton Antivirus 2005, the company said.

"Symantec strongly recommends that customers ensure their products are up-to-date to protect against this vulnerability," the company said in a statement. "To date, Symantec has not had any reports of related exploits of this vulnerability."

Security information company Secunia, which rates the seriousness of software vulnerabilities, gave the Symantec flaw its second-highest threat grade, "highly critical".

The problem exists in how the scanning code handles a compression format known as the Ultimate Packer for Executables (UPX). An attacker could create a virus designed to exploit the UPX flaw and send it to victims through email or host it on a Web site. An unpatched Symantec scanner checking incoming email or the Web pages that users browse would run the program instead of catching the virus.

"The vulnerability can be triggered by an unauthorized remote attacker, without user interaction, by sending an e-mail containing a crafted UPX file to the target," Internet Security Systems, the company that found the flaw, stated in an advisory on Tuesday. The company said it notified Symantec of the issue when it found it.

The flaw highlights the danger of weaknesses in the security software that acts as a gateway between the unfiltered Internet and internal corporate networks. Internet Security Systems experienced such problems firsthand a year ago, when a flaw in its own firewall software was targeted by a worm two days after the public release of an advisory.

Symantec is distributing patches to its customers through its LiveUpdate automatic update service and other mechanisms. It warned companies that do not use those services to download the patches from its Web site and apply them as soon as possible.

Internet Security Systems could not immediately provide a spokesperson to comment on the issue.

The announcement of the flaw happened the same day that Microsoft released a dozen patches to fix holes in its Windows operating system and other applications. Microsoft also announced it intended to buy security company Sybari, which would put the software giant in direct competition with Symantec.

Other products that use the Symantec antivirus scanning library include Symantec's Brightmail antispam software and Symantec Web Security.

  • Email
  • Trackback
  • Clip Link
  • Print friendly Print with Dell

Did you find this article useful?
94 out of 165 people found this useful


Full Talkback thread

0 comments

Company/Topic Alerts

Create a new alert from the list below:



Related Jobs

Java/Tomcat/Spring/HTML Developer - Sign off today - 500 per day

You will be creating a large document library involving both front-end pages for users of the library plus maintenance screens with facilities to ...

Security Document Manager

Administration of a Battlespace Secure item library. Assess the need for detailed work instructions and produce them * Consolidate secure items into ...

Analyst Programmer (fixed term 24 months)

London School of Economics and Political Science The Library Analyst Programmer (fixed term 24 months) Salary: 30,201 - 36,563 pa incl The Library is ...

Featured Talkback

What was achieved there is recognised to be of fundamental importance to both winning the war (Churchill visited to say 'thank you' to them) and the development of the computer. Maybe Bill Gates doesn't want to support this museum because it underlines where electronic computing started i.e. here, not the U.S.

By: 1000103773

Read full story:
Bletchley Park faces bleak future

Sentry Posts Blog

Skype - The Roach Motel

Here is an interesting article from The National Business Review, pointing out once again that you can never delete a Skype account. Never. Period. This is something I am familiar... More

Post a comment

The vPhone: Why Visa Should Go Mobile

The vPhone: Why Visa Should Go Mobile Author: Eric Everson, Founder MyMobiSafe.com With all of the success of Apple’s iPhone, there is a growing case to support a company like Visa... More

Post a comment

The Google Apple Merger: Fantasy or Fu...

The Google Apple Merger: Fantasy or Future? Author: Eric Everson, Founder MyMobiSafe.com Market research suggests that Microsoft controls upwards of 90% of the respective computer-based... More

2 comments