ZDNet UK


Skip to Main Content

ZDNet.co.uk - Winner of Best Business Website 2007
  1. Home
  2. News
  3. Blogs
  4. Reviews
  5. Prices
  6. Resources
  7. Community
  8. My ZDNet

 

ZDNet UK RSS Feeds


IT Jobs

Security threats Toolkit

Kaspersky confirms antivirus flaw

Joris Evers CNET News.com

Published: 05 Oct 2005 10:00 BST

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

Kaspersky Lab confirmed Tuesday that a potentially serious flaw exists in its antivirus software, but said a fix is on the way.

The security software maker said it had offered preliminary protection to customers last week and that a permanent patch will be available on Wednesday.

Kaspersky also said that the vulnerability is limited to Microsoft Windows-based versions of its products. Additionally, while it does license the vulnerable component to some third parties, most partner products that use Kaspersky code are not affected, the Moscow-based company said in a statement.

Kaspersky issued the statement in response to a report on Monday of a flaw in its antivirus library. An attacker could exploit the heap overflow vulnerability to commandeer systems that run Kaspersky's products, security researcher Alex Wheeler wrote in an advisory (download PDF).

"The actual threat posed by the...vulnerability is minimal and cannot affect the level of antivirus protection provided by Kaspersky Lab products," the company said in the statement.

Wheeler informed Kaspersky of the flaw around Sept. 24, said Stephen Orenberg, president of Kaspersky's North American operations. After an initial investigation, Kaspersky provided updated antivirus signatures on Sept. 29 to protect customers against attacks exploiting the flaw, he said. A final fix is due Wednesday, Orenberg said.

Affected products are: Kaspersky Anti-Virus Personal 5.0; Kaspersky Anti-Virus Personal Pro 5.0; Kaspersky Anti-Virus 5.0 for Windows Workstations; Kaspersky Anti-Virus 5.0 for Windows File Servers and Kaspersky Personal Security Suite 1.1.

"This is a theoretical flaw," Orenberg said. "There has never been an exploit for this flaw."

A hacker could launch a remote attack via the vulnerability by sending a malformed CAB file to a PC--in an e-mail, for example, the French Security Incident Response Team said in an advisory Monday. No user interaction is needed for the malicious code to run, FrSirt noted. The group gave the issue its highest rating of "critical."

As the pool of easily exploitable security bugs in Microsoft Windows dries up, attackers are looking for holes in security software as a way to get into systems, Yankee Group analysts wrote in a research paper released earlier this year.

At the Black Hat Briefings security conference this summer, researchers at Internet Security Systems outlined vulnerabilities in antivirus products. ISS has discovered bugs in products from security software makers including Symantec, McAfee, Trend Micro and F-Secure.

  • Email
  • Trackback
  • Clip Link
  • Print friendly Print with HP

Did you find this article useful?
90 out of 181 people found this useful


Full Talkback thread

0 comments


Company/Topic Alerts

Create a new alert from the list below:



Related Jobs

FIX Analyst / Support - Contract - Inv Banking - London

FIX Analyst / Support - Contract - Inv Banking - London This role is for an experienced FIX Protocol analyst. You will have a strong background and ...

Java Connectivity Developer Equities Trading - Java, FIX

From a technical perspective good Java experience is required, knowledge of UNIX and FIX is strongly preferred. Java/UNIX/FIX/ SYBASE. A Junior level ...

Systems Administrator - MCSE, Server, AD, Exchange, IIS, BES,C.London

Laptop management and support including hardware and software - Managing office hardware including printers and scanners - Active Directory ...

Sentry Posts Blog

Mobile Linux Better For Mobile Busines...

Mobile Linux Better For Mobile Business Apps? Author: Eric Everson, MyMobiSafe.com As mobile Linux is carving it’s footprint on the future of mobile application development, the... More

Post a comment

DWP downplays security breach

The Department for Work and Pensions (DWP) has admitted that some of its staff have been forwarding passwords with password protected material. An email that was leaked on the 'Dizzy... More

Post a comment

How many headshots does one chairperso...

We got a strange request last week from the head of PR from Russian security experts Kaspersky. It seems although the company was very happy with the interview we recently carried with... More

Post a comment

Featured Talkback

On the contrary, if vendors were forced to stand behind their products it should increase innovation. It would force more, and better , testing before hitting the sales floor, resulting in fewer updates and less downtime for the consumer. At present the EULA removes responsibility from the vendor, and moves it to the user, which is a step backward. Make the vendor responsibility for their code.

By: ator1940

Read full story:
RSA: Vendor liability may stifle innovation