On mySimon: Heys Athena 3 Piece Ultra Lite Luggage
BNET Business Network:
BNET
TechRepublic
ZDNet

By Karen Said
Posted on ZDNet News: Feb 11, 2005 10:23:00 PM

F-Secure has released a patch for a serious flaw in its antivirus products, the second time this week a security company has warned of a risk in its software.

The security hole in the antivirus library affects 18 products for desktops, servers and gateways, with the network products at "critical" risk, F-Secure said in a bulletin Thursday. By creating a specially crafted ARJ archive file, an intruder could use a buffer overflow to run arbitrary code on an unpatched machine, said Tony Magellanez, a systems engineer at F-Secure.

"At this point, it's a theoretical exploit," Magellanez said, noting that Internet Security Systems, which discovered the flaw, had not provided F-Secure with an example of malformed ARJ code. "ISS gave us details of how it could be done, and we created a patch."

The vulnerability could enable intruders to spy on confidential company information, ISS said in its advisory. It noted that several large vendors and Internet security providers use the antivirus library in their products.

F-Secure is urging all customers to apply the patch. Magellanez said businesses with managed security could use the policy manager to automatically send the update to individual users' machines. The fix has already been distributed to ISPs so they can get it out to members, Magellanez said.

On Tuesday, security software maker Symantec alerted its customers to a vulnerability in its own antivirus library, also found by ISS. The scanning software flaw, which affects the majority of Symantec's antivirus and antispam products, could cause a virus to execute, rather than catch it.

Internet Security Systems could not immediately provide a representative to comment on the issue.

SponsoredWhite Papers, Webcasts, and Downloads

  • Talkback
  • Most Recent of 26 Talkback(s)
my bad
meant to say F-Secure...got F-Prot on the brain. (Read the rest)
Posted by: IT Scion Posted on: 02/14/05 You are currently: a Guest | | Terms of Use
Windows is so full of holes ...  George Mitchell | 02/11/05
?  LinuxHippie | 02/11/05
The problem ultimately lies with Windows ...  George Mitchell | 02/11/05
You can't be serious  LinuxHippie | 02/12/05
He didn't say that, WinZealot  Jeff Spicoli | 02/12/05
I'm listening ...  George Mitchell | 02/12/05
Quick question  NonZealot | 02/12/05
Well I am not a newbie ...  George Mitchell | 02/12/05
George the expert  NonZealot | 02/12/05
2 Quick questions  Immanuel Tranz-Mischen | 02/13/05
I'll answer your quick questions  NonZealot | 02/13/05
So I'm not wasting my time any further...  LinuxHippie | 02/14/05
Add yet another one  IT Scion | 02/11/05
Windows is the ONLY OS that REQUIRES antivirus software ...  George Mitchell | 02/11/05
ID 10 T (NT)  LinuxHippie | 02/12/05
Hey wait a minute...  FreeBSD | 02/12/05
No it's not  seosamh_z | 02/13/05
News Flash  Immanuel Tranz-Mischen | 02/13/05
Re: News Flash  PA-ITGuy | 02/13/05
Since when is the OSX kernel...  ShadeTree | 02/14/05
Really?  IT Scion | 02/14/05
my bad  IT Scion | 02/14/05
All AV packages are brutal failures  osreinstall | 02/14/05
I do not run any AV package  osreinstall | 02/13/05
What cave are you living in?  Immanuel Tranz-Mischen | 02/13/05
A very secure cave - NT  osreinstall | 02/13/05

What do you think?

advertisement
advertisement
Click Here

White Papers, Webcasts, and Downloads

Meet Doc