Version: 2008
  • On CBS MoneyWatch: The perfect car for a teenager

March 17, 2005 1:56 PM PST

Another antivirus software flaw detected

  • 5 comments
For the fifth time in two months, security researchers have publicized a serious flaw in a widely used virus-scanning program.

The vulnerability affects McAfee's Antivirus Library, a collection of common code shared among the security software company's various virus scanners, including GroupShield for mail servers and VirusScan for PCs. An attacker could use the flaw to cause a vulnerable system to run a file instead of scanning it for malicious code.

While the company just learned of the issue recently, an update offered to corporate customers in November and consumers in December added security measures that fixed the problem.

"Once the update was released, all current subscribers got the fix," said Marc Solomon, senior product manager for McAfee. "For anyone who is no longer a subscriber, this is a reminder to renew."

The flaw is the fourth antivirus security vulnerability found by Internet Security Systems, which sells software and hardware to protect networks and corporate PCs. The company also has found flaws in the antivirus libraries developed by security software companies Symantec, F-Secure and Trend Micro. Another flaw in Computer Associates International's antivirus software was discovered by security firm eEye Digital Security.

Internet Security Systems would not specify how the problems were found, but a representative stressed that the company didn't target the products.

Users of McAfee's virus scanning software, also known as an engine, are vulnerable only if the software has not been updated through a current subscription and the person has not downloaded the latest virus definitions file, or DAT, from the company.

The flaw could be exploited using any type of network traffic that is scanned by a McAfee product, including e-mail, Web browsing and Windows file sharing. When the vulnerable software attempted to open a malicious file, the software would instead run the program included in the file.

The flaw occurs in how McAfee's software, based on the older library, scans files that are compressed using a format known as LHA. A specially crafted file, when scanned by vulnerable McAfee software, can execute its program.

See more CNET content tagged:
flaw, McAfee Inc., antivirus software, Internet Security Systems Inc., security software company

Add a Comment (Log in or register) (5 Comments)
  • prev
  • 1
  • next
Internet questionables
by March 17, 2005 2:36 PM PST
Why do I get the feeling that the internet community resembles the lottery community - deception from the top down?
Reply to this comment
lottery community
by John Kuzak June 1, 2007 2:56 PM PDT
http://www.analogstereo.com/nakamichi/nakamichi_480_service_manual.htm
Lemon Law for Software
by March 18, 2005 8:10 AM PST
I assert this article makes a case for software implied-warranty laws. A product was sold with the implied promise that it protects the buyer's computer; it should not expose the protected computer to new threats. Moreover, the buyer should not be forced to pay for a working version of the software. The principle is the same as automobile "lemon laws" and laws that enforce implied warranties that override manufacturer's serviceability disclaimers. Shrink-wrap and servisability disclaimers are too prevalent in the software industry.
Reply to this comment
just a thought...
by March 21, 2005 7:55 AM PST
Wouldn't it be funny, if some of these companies end up getting sued because they put out "joke" software. Were they say what they have will protect your system but in reality it's made to expose your systems flaws?

Wait there should be a "quack" law for security software. Some companies are legit and god bless em. but they need to deal with the ones that put software out that doesn't actually protect.
by antivirus-software December 27, 2008 5:20 PM PST
Macafee has been in the antivirus software business a long while
Reply to this comment
(5 Comments)
  • prev
  • 1
  • next
advertisement

Latest tech news headlines

RSS Feeds

Add headlines from CNET News to your homepage or feedreader.

More feeds available in our RSS feed index.

Markets

Market news, charts, SEC filings, and more

Related quotes

McAfee (0.02%) 0.01 43.19
Dow Jones Industrials (0.43%) 44.29 10,291.26
S&P 500 (0.50%) 5.50 1,098.51
NASDAQ (0.74%) 15.82 2,166.90
CNET TECH (0.52%) 8.18 1,579.76
  Symbol Lookup
advertisement

Inside CNET News

Scroll Left Scroll Right