You are here: silicon.com > Software > Security Strategy

Security Strategy

Symantec security hole puts systems at risk

Flaw in antivirus products...

Tags: flaw, antivirus, symantec

By Joris Evers

Published: 6 October 2005 08:55 GMT

A serious security flaw in part of Symantec's antivirus products puts enterprise systems running the software at risk of intrusion.

A buffer overflow flaw in the Symantec AntiVirus Scan Engine could let remote attackers run code on vulnerable machines, Symantec said in an advisory on Tuesday. The problem affects various versions of the engine, which is the part of the security software that actually scans for threats. Security patches are available to correct the problem, which Symantec rates "high" on its risk impact scale.

The company said in its alert: "Symantec strongly recommends all customers immediately apply the latest updates for their supported product versions to protect against these types of threats." No attacks that use the flaw have been reported, Symantec said.

The security hole lies in the web-based administrative interface of the Symantec Antivirus Scan Engine, the company said. This interface is part of several of the company's corporate antivirus products. An attacker could exploit it by sending a malformed request to the interface, security intelligence company iDefense said in an advisory. iDefense reported the flaw to Symantec.

Symantec advises people to check their installation. The administrative interface should be accessible only via a secure segment of the network and should never be open outside a company's network, Symantec said.

Disclosure of the Symantec issue is further evidence that researchers are increasingly looking for holes in security products. Protective technology is commonly installed on PCs, servers, network gateways and mobile devices. As security software becomes more widespread, it also becomes more attractive as a target to cyber criminals, experts have said.

Earlier this week a serious flaw in Kaspersky's antivirus products was disclosed.

Joris Evers writes for CNET News.com

  1. Zones
  2. Management
  3. Networks
  4. Software
  5. IT Services
  6. Hardware
  1. Verticals
  2. Public Sector
  3. Financial Services
  4. Retail & Leisure

Steve Ranger Editor's Blog: Is software's future now behind it? The industry is short on big ideas - at least for now

Tim Ferguson Is Salesforce.com sitting pretty for cloud wars? Comment: Software giants face a well prepared foe


  • Jobs
SEO Programming Manager

Support the company's Search Engine Optimisation (SEO) efforts by creating and optimizing content to establish keyword density objectives6. Such ...

Systems Engineer - Presales

Department Overview Symantec software is acknowledged as the sole leader in many market segments; from Enterprise back-up and recovery to email ...

Web Developer (ASP )

ASP, ASP.net, C#, SQL Server, HTML, CSS, XML, JavaScript, SEO Search Engine Optimisation, Web Standards W3C, Leeds. This will also include site code ...

Agenda Setters 2008
Welcome to the ninth annual Agenda Setters poll – silicon.com's list of the top 50 most influential individuals in the technology and IT industries, from techies and CIOs to entrepreneurs and business leaders. Find out more in our latest special report.





Quick Sitemap Links: