ZDNet UK


Skip to Main Content

ZDNet.co.uk - Winner of Best Business Website 2007
  1. Home
  2. News
  3. Blogs
  4. Reviews
  5. Prices
  6. Resources
  7. Community
  8. My ZDNet

 

ZDNet UK RSS Feeds


IT Jobs

Security threats Toolkit

F-Secure products are vulnerable, warns F-Secure

Tom Espiner ZDNet.co.uk

Published: 19 Jan 2006 17:20 GMT

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

Security company F-Secure on Thursday warned businesses of a critical vulnerability in its antivirus products.

In a security bulletin, F-Secure said that an attacker could execute the code of his choice on affected systems by using specially crafted ZIP files to circumvent F-Secure antivirus products and cause a buffer overflow. The flaw affects F-Secure products for both for Windows and Linux systems.

A buffer overflow occurs when a program tries to store too much data in a temporary data storage area, and is a common type of programming flaw that can be exploited.

F-Secure also found that hackers could create RAR and ZIP archives containing malware that cannot be scanned by its products, allowing the files to slip through a company's security defences.

F-Secure said it is not aware of any malware that exploits this vulnerability and has not yet seen any attacks, but recommends that businesses "patch now" to avoid attack.

Businesses using older F-Secure products are more at risk, especially those running Linux server and gateway products. Patches will not be distributed automatically for these products, so users must download them from the F-Secure site. For newer products such as F-Secure Internet Security 2004 — 2006, a patch was distributed automatically on Thursday afternoon.

For a full list of the products affected click here.

The vulnerability was found by security researcher Thierry Zoller, who disclosed the information to F-Secure.

  • Email
  • Trackback
  • Clip Link
  • Print friendly Print with Dell

Did you find this article useful?
95 out of 236 people found this useful


Full Talkback thread

0 comments


Company/Topic Alerts

Create a new alert from the list below:




Related Jobs

Senior Java Developer Fixed Income Swaps Pricing CDS

Knowledge of distributed computing/grid. Mixture of long term development projects and some Ad-Hoc programming as required. Leading Tier1 City ...

Fantastic opportunity for experienced Quantitative Developer

They are looking for an exceptional candidate who possesses the following: - 5+ years C/C++ programming experience with an understanding on how to ...

Firewalls Engineer Lead

On an operational level, you will support and enhance the firewalls and switches that provide the core gateway to the internet at the site. Provide ...

Featured Talkback

What was achieved there is recognised to be of fundamental importance to both winning the war (Churchill visited to say 'thank you' to them) and the development of the computer. Maybe Bill Gates doesn't want to support this museum because it underlines where electronic computing started i.e. here, not the U.S.

By: 1000103773

Read full story:
Bletchley Park faces bleak future

Sentry Posts Blog

Mobile Security Expert: Your Camera Ph...

Mobile Security Expert: Your Camera Phone Got Hacked Author: Eric Everson, Founder MyMobiSafe.com Have you ever heard someone say “I’d like to be a fly on the wall in that room.”?... More

Post a comment

Skype - The Roach Motel

Here is an interesting article from The National Business Review, pointing out once again that you can never delete a Skype account. Never. Period. This is something I am familiar... More

Post a comment

The vPhone: Why Visa Should Go Mobile

The vPhone: Why Visa Should Go Mobile Author: Eric Everson, Founder MyMobiSafe.com With all of the success of Apple’s iPhone, there is a growing case to support a company like Visa... More

Post a comment