On TechRepublic: Windows 7 report card: Hits and misses
BNET Business Network:
BNET
TechRepublic
ZDNet

By Joris Evers
Posted on ZDNet News: May 30, 2006 10:01:00 PM

Symantec over the weekend delivered fixes for a high-profile flaw in its corporate antivirus products that could be exploited in an Internet worm attack.

Users of Symantec AntiVirus Corporate Edition and Symantec Client Security should apply the appropriate update as soon as possible, Vincent Weafer, a senior director at Symantec Security Response, said Tuesday. However, because there are no known attacks that exploit the flaw, the need to patch is not urgent, he added.

The vulnerability was initially reported last week by eEye Digital Security. The flaw, a remotely exploitable buffer overflow, could potentially allow an attacker to run malicious code on a vulnerable computer. Because Symantec's software is so widely used, this could cause havoc on the Internet--for example, if a worm were to exploit the problem.

Recognizing the urgency to deliver a fix, Symantec worked over the weekend--a holiday weekend in the U.S.--to deliver patches. "Since it was publicly reported, we did have to go into emergency mode and deliver patches for the products," Weafer said.

Ubiquitous antivirus software is like low-hanging fruit to hackers, analysts have said. As the pool of easily exploitable Microsoft Windows bugs dries up, attackers are looking for holes in security software to break into PCs. Symantec realizes this, Weafer said.

"More eyes are looking for these vulnerabilities," he said. "This is clearly something we're going to look at ourselves. We can use this as a lesson to determine if there is any change needed to our secure programming."

Symantec has fixes available for the English versions of its products. The Cupertino, Calif., company is still working on updates for international versions. The products affected by this security issue are Symantec AntiVirus Corporate Edition version 10.x and Symantec Client Security version 3.x.

SponsoredWhite Papers, Webcasts, and Downloads

  • Talkback
  • Most Recent of 14 Talkback(s)
Panda
Hav you triend Panda Antivirus? (Read the rest)
Posted by: dwain.erhart@... Posted on: 01/17/07 You are currently: a Guest | | Terms of Use
Version Correction  Ludovit | 05/31/06
not to mention  Monkey_MCSE | 05/31/06
Symantec Pre-Installs  Too Old For IT | 05/31/06
Name one thing better.  Ludovit | 05/31/06
Envy?  Monkey_MCSE | 05/31/06
Not sure about Symantec in the corporate environment...  Zeppo9191 | 06/01/06
Panda  dwain.erhart@... | 01/17/07
Symantec Antivirus 2006  sparky466 | 05/31/06
Maybe you should read the instructions?  computerworkspro | 05/31/06
Symantec Antivirus 2006  sparky466 | 05/31/06
Read Much?  Geo.Frank | 05/31/06
Addressing your suggestions  Zeppo9191 | 06/01/06
Doing without symantec antivirus software  COMPUBRAIN | 05/31/06
This is why we used the consumer version  Resuna | 01/16/07

What do you think?

advertisement
advertisement

White Papers, Webcasts, and Downloads

SmartPlanet

  • Thought-provoking progressive ideas on diverse topics that intersect with technology, business, and life, and matter to the world at large. Visit SmartPlanet
  • More from IBM
  • Innovate your business' process model, play against the market, compete against others on our scoreboards and WIN! Try INNOV8 2.0: A BPM Simulator
  • Enabling Real-World Business Transformation through IBM Service Management Read the EMA Analyst Report
Click Here