Version: 2008

September 1, 2005 5:40 PM PDT

Symantec probes report of antivirus product flaw

  • Post a comment
Symantec is investigating a report of a weakness in the way its corporate antivirus software stores login credentials, the security vendor said on Wednesday.

Symantec's AntiVirus Corporate Edition 9.0 saves usernames and passwords in plain text in a log file when connecting to an internal LiveUpdate server for updates, according to a post on the Bugtraq mailing list. The credentials are stored in a fixed location on the computer that's accessible by any user, according to the bug report.

Symantec's Incident Response team has been notified of the suspected issue, a Symantec representative said on Thursday. "Symantec's product teams are evaluating the issue now and, if necessary, will provide a prompt response and solution," the representative said.

One scenario in which the user credentials could be abused is by a local attacker to gain higher privileges, according to the bug report.

As a workaround, users of AntiVirus Corporate Edition could set their systems to allow anonymous, read-only access to the LiveUpdate server, one Bugtraq reader advises. "The downside is that anyone can take a look at the state of your LiveUpdate files and might use version or product information against you in some way," the reader writes.

See more CNET content tagged:
Symantec Corp., BugTraq, antivirus software, antivirus, server

advertisement

Latest tech news headlines

RSS Feeds

Add headlines from CNET News to your homepage or feedreader.

More feeds available in our RSS feed index.

Markets

Market news, charts, SEC filings, and more

Related quotes

Symantec (-0.17%) -0.03 18.00
Dow Jones Industrials (0.13%) 13.75 10,533.85
S&P 500 (0.07%) 0.79 1,127.27
NASDAQ (0.23%) 5.23 2,290.92
CNET TECH (0.22%) 3.70 1,661.61
  Symbol Lookup
advertisement

Inside CNET News

Scroll Left Scroll Right