richcornucopia Posted December 21, 2005 CID Share Posted December 21, 2005 This again, reminds me why I refuse to use Symantec products. (except sygate) http://news.com.com/High+risk+in+Symantec+antivirus+software+flaw/2100-1002_3-6004097.html?tag=nefd.top Symantec's antivirus software contains a vulnerability that could be exploited by a malicious hacker to take control of a system, the company said late Tuesday. According to Symantec, the bug, which affects a range of the company's security products, is a "high" risk. Denmark security company Secunia has labeled it "highly critical." According to an advisory issued by Secunia, the bug affects most of Symantec's products, including enterprise and home user versions of Symantec AntiVirus, Symantec Norton AntiVirus and Symantec Norton Internet Security, across the Windows and Macintosh platforms. The vulnerability is within Symantec AntiVirus Library, which provides file format support for virus analysis. "During decompression of RAR files, Symantec is vulnerable to multiple heap overflows allowing attackers complete control of the system(s) being protected," said security consultant Alex Wheeler, who first discovered the flaw. "These vulnerabilities can be exploited remotely, without user interaction, in default configurations through common protocols such as SMTP." RAR is a native format for WinRAR, which is used to compress and decompress data. So far, the vulnerability has been reported in Dec2Rar.dll version 3.2.14.3 and, according to Wheeler, potentially affects all Symantec products that use the DLL. The full list of products affected can be seen here. Symantec has not yet released a patch to address this problem. In the meantime, Wheeler recommends that users "disable scanning of RAR-compressed files until the vulnerable code is fixed." This is not the first vulnerability Wheeler has discovered. In October, he highlighted a similar flaw in Kaspersky Lab's antivirus software, which was later acknowledged by the company. Again, it was a heap overflow vulnerability. In February, he found a different heap overflow vulnerability in Symantec's antivirus software. Quote Link to comment Share on other sites More sharing options...
RAINMAKA Posted December 21, 2005 CID Share Posted December 21, 2005 i was never really a fan of norton and this makes me glad that i dont use norton Quote Link to comment Share on other sites More sharing options...
dlewis23 Posted December 21, 2005 CID Share Posted December 21, 2005 I only need one reason not to use noton or Mcafee they slow do your computer, AVG is the best. Quote Link to comment Share on other sites More sharing options...
ghostmaster Posted December 21, 2005 CID Share Posted December 21, 2005 I use site licensed version of Symantec Corporate. Quote Link to comment Share on other sites More sharing options...
Blunted 2 Posted December 21, 2005 CID Share Posted December 21, 2005 i dont like them anymore but had faith in them in the past but i'm goin to kaspersky which has 2 scanning engines not 1 like norton. my friend told me alot about this and i want to but it. Quote Link to comment Share on other sites More sharing options...
bigw Posted December 22, 2005 CID Share Posted December 22, 2005 Trend all the way baby. Plus I got it for free! Quote Link to comment Share on other sites More sharing options...
supersteven Posted December 22, 2005 CID Share Posted December 22, 2005 God bless Kaspersky. Quote Link to comment Share on other sites More sharing options...
Recommended Posts
Join the conversation
You can post now and register later. If you have an account, sign in now to post with your account.
Note: Your post will require moderator approval before it will be visible.