Advertisement
Promo

Security threats Toolkit

Symantec flaw puts businesses at risk

Joris Evers CNET News

Published: 06 Oct 2005 10:05 BST

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

A serious security flaw in part of Symantec's antivirus products puts enterprise systems running the software at risk of intrusion.

A buffer overflow flaw in the Symantec AntiVirus Scan Engine could let remote attackers run code on vulnerable machines, Symantec said in an advisory on Tuesday. The problem affects various versions of the engine, which is the part of the security software that actually scans for threats. Security patches are available to correct the problem, which Symantec rates "high" on its risk impact scale.

"Symantec strongly recommends all customers immediately apply the latest updates for their supported product versions to protect against these types of threats," the company said in its alert. No attacks that use the flaw have been reported, Symantec said.

The security hole lies in the Web-based administrative interface of the Symantec Antivirus Scan Engine, the company said. This interface is part of several of the company's corporate antivirus products. An attacker could exploit it by sending a malformed request to the interface, security intelligence company iDefense said in an advisory. iDefense reported the flaw to Symantec.

Symantec advises people to check their installation. The administrative interface should be accessible only via a secure segment of the network and should never be open outside a company's network, Symantec said.

Disclosure of the Symantec issue is further evidence that researchers are increasingly looking for holes in security products. Protective technology is commonly installed on PCs, servers, network gateways and mobile devices. As it becomes more widespread, the more attractive a target security software becomes to cybercriminals, experts have said.

Earlier this week a serious flaw in Kaspersky's antivirus products was disclosed.

  • Email
  • Trackback
  • Clip Link
  • Print friendlyPrint with EPSON

Did you find this article useful?
62 out of 124 people found this useful


Full Talkback thread

0 comments

Company/Topic Alerts

Create a new alert from the list below:







Video icon

Video

Sentry Posts Blog

Official Organizations Losing Data

How does this article from earlier today make you feel? How many more government, health service, or military officials are going to lose pen drives, DVDs, USB hard disks and even entire... More

1 comment

Twitter hack was DNS redirect

Twitter has said an attack on Thursday which took the site offline for many users was the result of a DNS redirect. A group calling itself the Iranian Cyber Army redirected users... More

1 comment

McKinnon lawyers seek judicial review

Lawyers seeking a judicial review for Nasa hacker Gary McKinnon lodged fresh evidence of his psychiatric state at the High Court on Thursday. Karen Todner, McKinnon's solicitor,... More

1 comment

Win a BlackBerry with Vlingo voice recognition

Win a BlackBerry with Vlingo voice recognition

What is ZDNet UK's usual tagline?

Competition closes - 14 Jan 2010


Skip Sub Navigation Links to CNET Brand Links

Help

Become part of the ZDNet community.

Newsletters