Version: 2008
  • On CHOW: Why does asparagus make your pee smell?

October 5, 2005 2:51 PM PDT

Bug spotted in Symantec antivirus

  • 4 comments
A serious security flaw in part of Symantec's antivirus products puts enterprise systems running the software at risk of intrusion.

A buffer overflow flaw in the Symantec AntiVirus Scan Engine could let remote attackers run code on vulnerable machines, Symantec said in an advisory Tuesday. The problem affects various versions of the engine, which is the part of the security software that actually scans for threats. Security patches are available to correct the problem, which Symantec rates "high" on its risk impact scale.

"Symantec strongly recommends all customers immediately apply the latest updates for their supported product versions to protect against these types of threats," the company said in its alert. No attacks that use the flaw have been reported, Symantec said.

The security hole lies in the Web-based administrative interface of the Symantec Antivirus Scan Engine, the company said. This interface is part of several of the company's corporate antivirus products. An attacker could exploit it by sending a malformed request to the interface, security intelligence company iDefense said in an advisory. iDefense reported the flaw to Symantec.

Symantec advises people to check their installation. The administrative interface should be accessible only via a secure segment of the network and should never be open outside a company's network, Symantec said.

Disclosure of the Symantec issue is further evidence that researchers are increasingly looking for holes in security products. Protective technology is commonly installed on PCs, servers, network gateways and mobile devices. As it becomes more widespread, the more attractive a target security software becomes to cybercriminals, experts have said.

Earlier this week a serious flaw in Kaspersky's antivirus products was disclosed.

See more CNET content tagged:
Symantec Corp., Symantec AntiVirus, antivirus product, iDefense, attacker

Add a Comment (Log in or register) (4 Comments)
  • prev
  • 1
  • next
And this is the product...
by Norseman October 6, 2005 9:26 AM PDT
...Symantec wants me to use to protect my Mac, huh? Oh, yeah. I'm
gonna run right out and get me one!
Reply to this comment
reply
by October 12, 2005 4:16 PM PDT
HAHA. Av makes help fight against malicious codes and viruses, trojans, worms, etc, but yet, they left a big flaw in their software. Well atleast they fixed it.. but what if they havent yet, and I just read this and decide to go out and use this exploit. They should make a press release after its fixed, and only notify it's customers of this hole.
And this is the product...
by Norseman October 6, 2005 9:26 AM PDT
...Symantec wants me to use to protect my Mac, huh? Oh, yeah. I'm
gonna run right out and get me one!
Reply to this comment
reply
by October 12, 2005 4:16 PM PDT
HAHA. Av makes help fight against malicious codes and viruses, trojans, worms, etc, but yet, they left a big flaw in their software. Well atleast they fixed it.. but what if they havent yet, and I just read this and decide to go out and use this exploit. They should make a press release after its fixed, and only notify it's customers of this hole.
(4 Comments)
  • prev
  • 1
  • next

Latest tech news headlines

RSS Feeds

Add headlines from CNET News to your homepage or feedreader.

More feeds available in our RSS feed index.

Markets

Market news, charts, SEC filings, and more

Related quotes

Symantec (-0.34%) -0.06 17.65
Dow Jones Industrials (0.20%) 20.03 10,246.97
S&P 500 (-0.01%) -0.07 1,093.01
NASDAQ (-0.14%) -2.98 2,151.08
CNET TECH (0.21%) 3.30 1,571.59
  Symbol Lookup
advertisement

Inside CNET News

Scroll Left Scroll Right