AplusWebMaster
Topic Starter
FYI…
- http://news.yahoo.com/s/ap/20060525/ap_on_…/antivirus_flaw
May 25, 2006
"WASHINGTON - Symantec Corp.'s leading antivirus software, which protects some of the world's largest corporations and U.S. government agencies, suffers from a flaw that lets hackers seize control of computers to steal sensitive data, delete files or implant malicious programs, researchers said Thursday. Symantec said it was investigating the issue but could not immediately corroborate the vulnerability. If confirmed, the threat to computer users would be severe because the security software is so widely used, and because no action is required by victims using the latest versions of Norton Antivirus to suffer a crippling attack over the Internet. Symantec has boasted its antivirus products are installed on more than 200 million computers. A spokesman, Mike Bradshaw, said the company was examining the reported flaw but described it as "so new that we don't have any details." Researchers from eEye Digital Security Inc. of Aliso Viejo, Calif., discovered the vulnerability and provided evidence to Symantec engineers this week, said eEye's chief hacking officer, Marc Maiffret… a note about the company's discovery on its Web site but pledged not to reveal details publicly that would help hackers attack Internet users until after Symantec repairs its antivirus software…"
- http://www.eeye.com/html/research/upcoming/20060524.html
Date Reported: May 24, 2006
Vendor: Symantec
Description:
A remotely exploitable vulnerability exists within the Symantec Antivirus program. This flaw does not require any end user interaction for exploitation and can compromise affected systems, allowing for the execution of malicious code with SYSTEM level access.
Severity: High (Remote Code Execution)
Remote Code Execution: Yes
Software Affected:
- Symantec Antivirus 10.x
- Symantec Client Security 3.x
(Other Symantec Antivirus products are also potentially affected, waiting for vendor list) …"

- http://news.yahoo.com/s/ap/20060525/ap_on_…/antivirus_flaw
May 25, 2006
"WASHINGTON - Symantec Corp.'s leading antivirus software, which protects some of the world's largest corporations and U.S. government agencies, suffers from a flaw that lets hackers seize control of computers to steal sensitive data, delete files or implant malicious programs, researchers said Thursday. Symantec said it was investigating the issue but could not immediately corroborate the vulnerability. If confirmed, the threat to computer users would be severe because the security software is so widely used, and because no action is required by victims using the latest versions of Norton Antivirus to suffer a crippling attack over the Internet. Symantec has boasted its antivirus products are installed on more than 200 million computers. A spokesman, Mike Bradshaw, said the company was examining the reported flaw but described it as "so new that we don't have any details." Researchers from eEye Digital Security Inc. of Aliso Viejo, Calif., discovered the vulnerability and provided evidence to Symantec engineers this week, said eEye's chief hacking officer, Marc Maiffret… a note about the company's discovery on its Web site but pledged not to reveal details publicly that would help hackers attack Internet users until after Symantec repairs its antivirus software…"
- http://www.eeye.com/html/research/upcoming/20060524.html
Date Reported: May 24, 2006
Vendor: Symantec
Description:
A remotely exploitable vulnerability exists within the Symantec Antivirus program. This flaw does not require any end user interaction for exploitation and can compromise affected systems, allowing for the execution of malicious code with SYSTEM level access.
Severity: High (Remote Code Execution)
Remote Code Execution: Yes
Software Affected:
- Symantec Antivirus 10.x
- Symantec Client Security 3.x
(Other Symantec Antivirus products are also potentially affected, waiting for vendor list) …"