AplusWebMaster
Topic Starter
FYI…
- http://isc.sans.org/diary.php?storyid=1947
Last Updated: 2006-12-16 19:51:27 UTC
- http://www.informationweek.com/shared/prin…cleID=196700262
Dec. 15, 2006 - "A "significant" worm is successfully attacking unpatched Symantec enterprise anti-virus software because companies focus too much attention on Microsoft's flaws and ignore those from other vendors, a security company warned Friday. "Big Yellow," the name eEye Digital Security* has given the worm, was first captured Thursday by one of the company's honeypot systems. The worm, which also has a botnet component that turns a victimized machine into a zombie at the beck and call of its controller, exploits a critical vulnerability in Symantec AntiVirus and Symantec Client Security, two of the vendor's business security products. That vulnerability was reported to Symantec by eEye in May; the former fixed the flaw in June. Symantec's first notice of the vulnerability in AntiVirus and Client Security was posted May 26**, and patches were made available June 6. On Nov. 29, Symantec made note of the release of exploit code… Symantec's current advice is to patch Symantec AntiVirus and Client Security to protect systems against threats such as Big Yellow. A detailed guide on what versions must be patched and how is available on the Symantec support site***."
* http://research.eeye.com/html/alerts/AL20061215.html
** http://www.symantec.com/avcenter/security/…2006.05.25.html
*** http://service1.symantec.com/SUPPORT/ent-s…006052609181248
- http://www.symantec.com/enterprise/securit…-99&tabid=2
Updated: December 15, 2006
"…SUMMARY: W32.Sagevo is a worm that spreads by exploiting the Symantec Client Security and Symantec AntiVirus Elevation of Privilege (as described in Symantec Advisory SYM06-010**) and lowers security settings…"

- http://isc.sans.org/diary.php?storyid=1947
Last Updated: 2006-12-16 19:51:27 UTC
- http://www.informationweek.com/shared/prin…cleID=196700262
Dec. 15, 2006 - "A "significant" worm is successfully attacking unpatched Symantec enterprise anti-virus software because companies focus too much attention on Microsoft's flaws and ignore those from other vendors, a security company warned Friday. "Big Yellow," the name eEye Digital Security* has given the worm, was first captured Thursday by one of the company's honeypot systems. The worm, which also has a botnet component that turns a victimized machine into a zombie at the beck and call of its controller, exploits a critical vulnerability in Symantec AntiVirus and Symantec Client Security, two of the vendor's business security products. That vulnerability was reported to Symantec by eEye in May; the former fixed the flaw in June. Symantec's first notice of the vulnerability in AntiVirus and Client Security was posted May 26**, and patches were made available June 6. On Nov. 29, Symantec made note of the release of exploit code… Symantec's current advice is to patch Symantec AntiVirus and Client Security to protect systems against threats such as Big Yellow. A detailed guide on what versions must be patched and how is available on the Symantec support site***."
* http://research.eeye.com/html/alerts/AL20061215.html
** http://www.symantec.com/avcenter/security/…2006.05.25.html
*** http://service1.symantec.com/SUPPORT/ent-s…006052609181248
- http://www.symantec.com/enterprise/securit…-99&tabid=2
Updated: December 15, 2006
"…SUMMARY: W32.Sagevo is a worm that spreads by exploiting the Symantec Client Security and Symantec AntiVirus Elevation of Privilege (as described in Symantec Advisory SYM06-010**) and lowers security settings…"