'High' risk in Symantec antivirus software flaw

GEC: Discuss gaming, computers and electronics and venture into the bizarre world of STGODs.

Moderator: Thanas

Post Reply
User avatar
theski
Sith Marauder
Posts: 4327
Joined: 2003-01-28 03:20pm
Location: Hurricane Watching

'High' risk in Symantec antivirus software flaw

Post by theski »

:shock: Thank god they are a Anti-virus company :roll:
Symantec's antivirus software contains a vulnerability that could be exploited by a malicious hacker to take control of a system, the company said late Tuesday.

According to Symantec, the bug, which affects a range of the company's security products, is a "high" risk. Denmark security company Secunia has labeled it "highly critical."

According to an advisory issued by Secunia, the bug affects most of Symantec's products, including enterprise and home user versions of Symantec AntiVirus, Symantec Norton AntiVirus and Symantec Norton Internet Security, across the Windows and Macintosh platforms.

The vulnerability is within Symantec AntiVirus Library, which provides file format support for virus analysis. "During decompression of RAR files, Symantec is vulnerable to multiple heap overflows allowing attackers complete control of the system(s) being protected," said security consultant Alex Wheeler, who first discovered the flaw. "These vulnerabilities can be exploited remotely, without user interaction, in default configurations through common protocols such as SMTP."

RAR is a native format for WinRAR, which is used to compress and decompress data. So far, the vulnerability has been reported in Dec2Rar.dll version 3.2.14.3 and, according to Wheeler, potentially affects all Symantec products that use the DLL. The full list of products affected can be seen here.

Symantec has not yet released a patch to address this problem. In the meantime, Wheeler recommends that users "disable scanning of RAR-compressed files until the vulnerable code is fixed."

This is not the first vulnerability Wheeler has discovered. In October, he highlighted a similar flaw in Kaspersky Lab's antivirus software, which was later acknowledged by the company. Again, it was a heap overflow vulnerability.

In February, he found a different heap overflow vulnerability in Symantec's antivirus software.
RISK
Sudden power is apt to be insolent, sudden liberty saucy; that behaves best which has grown gradually.
User avatar
Einhander Sn0m4n
Insane Railgunner
Posts: 18630
Joined: 2002-10-01 05:51am
Location: Louisiana... or Dagobah. You know, where Yoda lives.

Post by Einhander Sn0m4n »

Just in time for me to have switched to AVG a month ago... Screw you Norton!
Image Image
User avatar
Soontir C'boath
SG-14: Fuck the Medic!
Posts: 6860
Joined: 2002-07-06 12:15am
Location: Queens, NYC I DON'T FUCKING CARE IF MANHATTEN IS CONSIDERED NYC!! I'M IN IT ASSHOLE!!!
Contact:

Post by Soontir C'boath »

I couldn't believe the school's techies approve Symantec as a reliable anti-virus program when we had a dorm meeting talking about requirements of what we need on our comp to be able to use the internet next semester. If this doesn't change their mind not to use Symantec then they are the worse tech support in the damn world.

Besides, who in their right minds would even use Symantec? It's a piece of garbage from the get go.
I have almost reached the regrettable conclusion that the Negro's great stumbling block in his stride toward freedom is not the White Citizen's Counciler or the Ku Klux Klanner, but the white moderate, who is more devoted to "order" than to justice; who constantly says: "I agree with you in the goal you seek, but I cannot agree with your methods of direct action"; who paternalistically believes he can set the timetable for another man's freedom; who lives by a mythical concept of time and who constantly advises the Negro to wait for a "more convenient season."
User avatar
Stark
Emperor's Hand
Posts: 36169
Joined: 2002-07-03 09:56pm
Location: Brisbane, Australia

Post by Stark »

Norton AV has sucked for years. Does anyone CHOOSE it, or does it just exist off the installed fanbase of mum-and-dad prepacked puters?
User avatar
Bounty
Emperor's Hand
Posts: 10767
Joined: 2005-01-20 08:33am
Location: Belgium

Post by Bounty »

Stark wrote:Norton AV has sucked for years. Does anyone CHOOSE it, or does it just exist off the installed fanbase of mum-and-dad prepacked puters?
I know precisely one (1) person who bought Norton, and that was only for the free MP3 player included in the bundle.
User avatar
Jawawithagun
Jedi Master
Posts: 1141
Joined: 2002-10-10 07:05pm
Location: Terra Secunda

Post by Jawawithagun »

It seems to come on every system sold by the big chains.
"I said two shot to the head, not three." (Anonymous wiretap, Dallas, TX, 11/25/63)

Only one way to make a ferret let go of your nose - stick a fag up its arse!

there is no god - there is no devil - there is no heaven - there is no hell
live with it
- Lazarus Long
User avatar
Chardok
GET THE FUCK OFF MY OBSTACLE!
Posts: 8488
Joined: 2003-08-12 09:49am
Location: San Antonio

Post by Chardok »

Einhander Sn0m4n wrote:Just in time for me to have switched to AVG a month ago... Screw you Norton!
Hah. sounds like you and I switched at exactly the same time. I went to AVG and deleted Norton within 30 minutes of each other, and I will never look back. WOO HOO! Safety through obscurity!
Image
User avatar
Faram
Bastard Operator from Hell
Posts: 5271
Joined: 2002-07-04 07:39am
Location: Fighting Polarbears

Post by Faram »

Muhaha, more work for me!

I just have to maile the allert to some customers and I am in the clear!

Either they pay me to upgrade their old crummy norton installations or they will not.

In that case I can tell them to fuck off if they get into ANY troubble and blame Norton, when that is done I fix the problem for *4 as much.

Sadly I cannot do this with Microsoft updates, I path their system 1/month but this is a bonus :)

And no I did not install norton to begin with, I "inherited" the existing systems.
[img=right]http://hem.bredband.net/b217293/warsaban.gif[/img]

"Either God wants to abolish evil, and cannot; or he can, but does not want to. ... If he wants to, but cannot, he is impotent. If he can, but does not want to, he is wicked. ... If, as they say, God can abolish evil, and God really wants to do it, why is there evil in the world?" -Epicurus


Fear is the mother of all gods.

Nature does all things spontaneously, by herself, without the meddling of the gods. -Lucretius
User avatar
Stark
Emperor's Hand
Posts: 36169
Joined: 2002-07-03 09:56pm
Location: Brisbane, Australia

Post by Stark »

Amusingly, this is how I encounter Norton AV myself: it fucking up, or being unusable, or whatever and the user paying me to use something else. Hilarious.
User avatar
dacis2
Youngling
Posts: 92
Joined: 2002-11-22 07:25pm
Location: Singapore, Singapore

Post by dacis2 »

Uhm... what's AVG?
User avatar
Jawawithagun
Jedi Master
Posts: 1141
Joined: 2002-10-10 07:05pm
Location: Terra Secunda

Post by Jawawithagun »

AVG Anti-Virus
Good enough that I even shelled out money for it.
"I said two shot to the head, not three." (Anonymous wiretap, Dallas, TX, 11/25/63)

Only one way to make a ferret let go of your nose - stick a fag up its arse!

there is no god - there is no devil - there is no heaven - there is no hell
live with it
- Lazarus Long
Post Reply