ZDNet UK


Skip to Main Content

ZDNet.co.uk - Winner of Best Business Website 2007
  1. Home
  2. News
  3. Blogs
  4. Reviews
  5. Prices
  6. Resources
  7. Community
  8. My ZDNet

 

ZDNet UK RSS Feeds


IT Jobs

Security threats Toolkit

Symantec security products hit by high-risk flaw

Colin Barker ZDNet.co.uk

Published: 21 Dec 2005 13:00 GMT

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

Symantec's antivirus software contains a vulnerability that could be exploited by a malicious hacker to take control of a system, the company admitted late on Tuesday.

According to Symantec the bug, which affects a range of the company's security products, is a "high" risk, while the Danish security specialists Secunia have labelled it as "highly critical".

According to an advisory issued by Secunia, the bug affects most of Symantec's products, including enterprise and home user versions of Symantec AntiVirus, Symantec Norton AntiVirus and Symantec Norton Internet Security, across both the Windows and Macintosh platforms.

The vulnerability is within Symantec AntiVirus Library, which provides file format support for virus analysis. "During decompression of RAR files, Symantec is vulnerable to multiple heap overflows allowing attackers complete control of the system(s) being protected," said security consultant Alex Wheeler, who first discovered the flaw. "These vulnerabilities can be exploited remotely, without user interaction, in default configurations through common protocols such as SMTP."

RAR is a native format for WinRAR, which is used to compress and decompress data. So far the vulnerability has been reported in Dec2Rar.dll version 3.2.14.3 and, according to Wheeler, potentially affects all Symantec products that use the DLL. The full list of products affected can be seen here.

Symantec has not yet released a patch to address this problem. In the meantime, Wheeler recommends that users "disable scanning of RAR compressed files until the vulnerable code is fixed".

This is not the first vulnerability that Wheeler has discovered. In October, he highlighted a similar flaw in Kaspersky Labs' antivirus software which was later acknowledged by the company. Again it was a heap overflow vulnerability.

In February he signalled a different heap overflow vulnerability in Symantec's antivirus software.

  • Email
  • Trackback
  • Clip Link
  • Print friendly Print with Dell

Did you find this article useful?
63 out of 168 people found this useful



Company/Topic Alerts

Create a new alert from the list below:









Related Jobs

SENIOR IT SECURITY ANALYST- ISO27001 - WOLVERHAMPTON

Working to ISO 27001 standard, you will take the lead in risk & vulnerability assessments and department auditing. Senior IT Security Analyst opening ...

Regulatory Analyst - Gloucestershire

You will be part of the unit Trust Department, a team of 22, and you will be required to read & understand the papers and updates on compliance / ...

IT Service Desk / Infrastructure / Systems Support Graduate Vacancies - London

Our vision is to help the most vulnerable children and young people break through injustice, deprivation and inequality, so they can achieve their ...

Featured Talkback

What was achieved there is recognised to be of fundamental importance to both winning the war (Churchill visited to say 'thank you' to them) and the development of the computer. Maybe Bill Gates doesn't want to support this museum because it underlines where electronic computing started i.e. here, not the U.S.

By: 1000103773

Read full story:
Bletchley Park faces bleak future

Sentry Posts Blog

Mobile Security Expert: Your Camera Ph...

Mobile Security Expert: Your Camera Phone Got Hacked Author: Eric Everson, Founder MyMobiSafe.com Have you ever heard someone say “I’d like to be a fly on the wall in that room.”?... More

Post a comment

Skype - The Roach Motel

Here is an interesting article from The National Business Review, pointing out once again that you can never delete a Skype account. Never. Period. This is something I am familiar... More

Post a comment

The vPhone: Why Visa Should Go Mobile

The vPhone: Why Visa Should Go Mobile Author: Eric Everson, Founder MyMobiSafe.com With all of the success of Apple’s iPhone, there is a growing case to support a company like Visa... More

Post a comment