• On BNET: 3 worst things about the iPhone 3G S

October 3, 2005 2:24 PM PDT

Flaw found in Kaspersky antivirus

  • 4 comments
A "critical" flaw in Kaspersky Lab's antivirus software could let an attacker commandeer systems that use the products, a security researcher warned Monday.

The problem lies in Kaspersky's antivirus library, security researcher Alex Wheeler wrote in an advisory (download PDF of advisory here). The vulnerability likely affects multiple Kaspersky products on various platforms because the library is used throughout the company's consumer and corporate software, he said.

Additionally, third-party products that use Kaspersky's antivirus technology could also be vulnerable, Wheeler said.

A remote attacker could exploit the heap overflow flaw by sending a malformed CAB file--a compression file--to a vulnerable system, the French Security Incident Response Team said in an advisory. The CAB file could be sent in an e-mail, for example, and once the Kaspersky antivirus scanner had accepted it, the malicious code would be in the system. No user interaction is required, Wheeler said. FrSirt describes the issue as "critical," its highest rating.

A representative for Kaspersky in Moscow could not immediately comment on the issue and said that the Russian company would need to investigate.

Antivirus software is like low-hanging fruit to hackers, Yankee Group analysts wrote in a research paper released earlier this year. As the pool of easily exploitable security bugs in Microsoft Windows dries up, attackers are looking to security software for holes to get into systems, the analysts said.

At the Black Hat Briefings security conference this summer, researchers at Internet Security Systems outlined vulnerabilities in antivirus products. ISS has discovered bugs in products from security software makers including Symantec, McAfee, Trend Micro and F-Secure.

See more CNET content tagged:
Kaspersky Lab, advisory, antivirus software, flaw, researcher

Add a Comment (Log in or register) (4 Comments)
  • prev
  • 1
  • next
Just trying to kill the concurent!
by October 5, 2005 8:09 AM PDT
If u have even very basic software knowledge and windows security, u understand that if u run anything on ur machine having Administrator privileges this program/software can do anything with ur PC. So if u are stupid enough to get libraries from some unknown person and replace ur current one with it how come it is only a problem of Kaspersky antivirus. If u replace library of Norton Or McKaffy antivirus u ?ll get exactly the same result, don?t u? So why is this guy screaming about a hole in Kaspersky antivirus only? Maybe he was paid to stop this software from spreading. U know, most people don?t know a lot of how it works but it will stay in their minds that ?kaspersky is bad?. This is just a cheap trick to kill the concurrent company!
Reply to this comment
Exactly, my friend...
by peaceguy October 25, 2005 12:15 AM PDT
You said a mouthful, amigo. You put the cards on the table. There is definitely something fishy going on here...

And thank you CNet, for spreading FUD, without at least mentioning in your story what this fellow is referring to...
Just trying to kill the concurent!
by October 5, 2005 8:09 AM PDT
If u have even very basic software knowledge and windows security, u understand that if u run anything on ur machine having Administrator privileges this program/software can do anything with ur PC. So if u are stupid enough to get libraries from some unknown person and replace ur current one with it how come it is only a problem of Kaspersky antivirus. If u replace library of Norton Or McKaffy antivirus u ?ll get exactly the same result, don?t u? So why is this guy screaming about a hole in Kaspersky antivirus only? Maybe he was paid to stop this software from spreading. U know, most people don?t know a lot of how it works but it will stay in their minds that ?kaspersky is bad?. This is just a cheap trick to kill the concurrent company!
Reply to this comment
Exactly, my friend...
by peaceguy October 25, 2005 12:15 AM PDT
You said a mouthful, amigo. You put the cards on the table. There is definitely something fishy going on here...

And thank you CNet, for spreading FUD, without at least mentioning in your story what this fellow is referring to...
(4 Comments)
  • prev
  • 1
  • next
advertisement

Latest tech news headlines

RSS Feeds

Add headlines from CNET News to your homepage or feedreader.

More feeds available in our RSS feed index.

Markets

Market news, charts, SEC filings, and more

Related quotes

Computer Associates International Inc. (-0.72%) -0.12 16.44
Dow Jones Industrials (-0.45%) -36.65 8,146.52
S&P 500 (-0.40%) -3.55 879.13
NASDAQ (0.20%) 3.48 1,756.03
CNET TECH (0.36%) 4.57 1,262.65
  Symbol Lookup
advertisement

Inside CNET News

Scroll Left Scroll Right