ZDNet UK


Skip to Main Content

ZDNet.co.uk - Winner of Best Business Website 2007
  1. Home
  2. News
  3. Blogs
  4. Reviews
  5. Prices
  6. Resources
  7. Community
  8. My ZDNet

 

ZDNet UK RSS Feeds


IT Jobs

Security threats Toolkit

Secunia: CA backup product 'inherently insecure'

Tom Espiner ZDNet.co.uk

Published: 16 Jan 2008 12:55 GMT

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

Some CA products containing antivirus components have "inherent code problems", according to vulnerability-testing company Secunia, which published its annual report on security vulnerabilities on Monday.

One CA product particularly criticised by Secunia was ARCserve Backup, which the security company said was poorly coded.

"ARCserve is inherently insecure," Thomas Kristensen, Secunia's chief technology officer, told ZDNet.co.uk on Tuesday. "It's poor code, with a poor design. An internal code review should have revealed problems in the code that needed to be fixed before the product was launched."

In a statement sent to ZDNet.co.uk, CA said that it was improving its quality-assurance procedures.

"CA takes software security very seriously," said the statement. "CA works continuously to prevent and proactively identify and address vulnerabilities. We have rigorous quality-control measures in place for our software, and we continue to improve those measures."

ARCserve Backup, a CA data-protection product with in-built antivirus and encryption functionality, had multiple vulnerabilities reported in June 2007, said Secunia. These included flaws which could have led to stack-based buffer overflows, enabling attackers to compromise systems, according to a Secunia advisory.

Those errors were reported to CA, which pushed out a patch that fixed some of the code problems, said Secunia.

However, when Secunia researchers analysed the patched product, they discovered that approximately 60 reported vulnerabilities were still present, according to the Secunia 2007 Report.

Secunia claimed its analysis revealed these vulnerabilities were partly due to the nature of the product code itself, and that vulnerabilities remain.

"Unless an overhaul of the code is undertaken, then the product remains susceptible to similar types of vulnerabilities," stated the report.

Thomas Kristensen said it was "surprising" to see 60 vulnerabilities in one product alone, but that it was more surprising that a patched product contained some of the same vulnerabilities, especially as it was patched by a security vendor.

"It's bizarre to see a patched product with vulnerabilities coming from a security vendor," said Kristensen. "It's not very smart to have vulnerabilities in a backup solution, as it's deployed on every workstation on a system, making the system more vulnerable."

CA declined to comment on how effective its ARCserve patch had been.

Read this

Feature
Special report: Anatomy of a hack attack

We recreate a typical attack on two large organisations

Read more +

Security vendor Symantec was also criticised in the Secunia report, for its use of the third-party Autonomy KeyView software development kit in Symantec Mail Security. According to a Secunia advisory, Autonomy KeyView, which is used in Symantec Mail Security as a Lotus 1-2-3 file viewer, can be exploited to cause buffer overflows when a specially crafted file is checked. Labelled "highly critical" by Secunia, the flaw could allow remote execution of arbitrary code.

Although the issue was reported on 12 December, the vulnerability remains unpatched, according to Secunia. Kristensen said that the problem faced by Symantec was that it was reliant on a third party to provide a patch.

"Vendors buy software from third parties to add functionality. The problem with KeyView is it is third-party software [that] Symantec can't control — they rely on someone else to get the update, " said Kristensen.

Kristensen added that there doesn't seem to be a well-established communication channel between Symantec, Autonomy and IBM, which is also affected.

"Ideally IBM, Symantec and Autonomy would push out patches on the same day," said Kristensen.

Symantec said that its product-security team "has identified an issue with a third-party component that is included in some versions of Symantec Mail Security". The company added that it is working on a solution.

"Because we take the security of our products very seriously, we published detailed mitigation instructions to protect customers immediately and have subsequently issued product updates [for some of the vendors affected] as well," said Wayne Periman, director of development for Symantec Security Response.

  • Email
  • Trackback
  • Clip Link
  • Print friendly Print with HP

Did you find this article useful?
5 out of 5 people found this useful


Full Talkback thread

0 comments

Company/Topic Alerts

Create a new alert from the list below:










Related Jobs

3rd Line Support - Infrastructure - North Yorkshire - 35000

Directory/Group Policy - Cisco Switches/Routers (to CCNA level or equivalent knowledge) -Cisco Firewalls (PIX or ASA) - LAN/WAN/WiFi Technologies ...

Backup Administrator - Windows, Veritas, Legato, Netbackup, Omniback - West London

Backup Administrator - Windows, Veritas, Legato, Netbackup, Omniback - West London Rackspace is a fast growing managed hosting company, which has ...

Systems Engineer - Microsoft

The right candidate will also have skills in security and backup: Veritas Netbackup 6.0 and Symantec Antivirus. Microsoft System Administrator ...

Sentry Posts Blog

Mobile Linux Better For Mobile Busines...

Mobile Linux Better For Mobile Business Apps? Author: Eric Everson, MyMobiSafe.com As mobile Linux is carving it’s footprint on the future of mobile application development, the... More

Post a comment

DWP downplays security breach

The Department for Work and Pensions (DWP) has admitted that some of its staff have been forwarding passwords with password protected material. An email that was leaked on the 'Dizzy... More

Post a comment

How many headshots does one chairperso...

We got a strange request last week from the head of PR from Russian security experts Kaspersky. It seems although the company was very happy with the interview we recently carried with... More

Post a comment

Featured Talkback

On the contrary, if vendors were forced to stand behind their products it should increase innovation. It would force more, and better , testing before hitting the sales floor, resulting in fewer updates and less downtime for the consumer. At present the EULA removes responsibility from the vendor, and moves it to the user, which is a step backward. Make the vendor responsibility for their code.

By: ator1940

Read full story:
RSA: Vendor liability may stifle innovation