On CBSNews.com: Can 365 Nights Of Sex Fix A Marriage?
BNET Business Network:
BNET
TechRepublic
ZDNet

By Dawn Kawamoto
Posted on ZDNet News: Feb 8, 2007 6:04:00 PM

Trend Micro is warning of a serious security flaw in several of its products that could cause a vulnerable PC to crash or be hijacked.

The flaw in its antivirus scan engine could be used to trigger a buffer overflow using a corrupted UPX file, the software maker said in an advisory issued earlier this week. For example, an outsider could send an e-mail with the malicious file to a computer loaded with the affected antivirus software.

As a result, the PC could suffer a "blue screen of death" or allow the attacker to remotely execute code and take control of the system, Trend Micro said.

Security companies such as Secunia have rated the flaw as "highly critical." There are no exploits for the vulnerability circulating yet, Trend Micro said.

The flaw affects all of Trend Micro's products that use its scan engine and pattern file technology, including its PC-cillin line and certain versions of Client Server Messaging Security for SMB. The at-risk software makes up a wide swath of its product line.

Experts have said that antivirus software is becoming more attractive as a target for hackers. In January, Symantec acknowledged that a known hole in its corporate antivirus tool was coming under persistent attack from worms.

Trend Micro credits iDefense Vulnerability Labs, which offers a bounty to bug hunters, for reporting the problem.

The antivirus software maker is advising customers to make sure the virus pattern file for their software is updated, either manually or via automatic updates, to pattern 4.245.00. It said that it will make enhancements to its scan engine and that it plans to apply a fix with its upcoming release of Scan Engine version 8.5.

  • Talkback
  • Most Recent of 41 Talkback(s)
I don't even use them
This is my dad's computer I'm talking about. He's had this problem on both his computers and his laptop. And as I go to his house every weekend, and have occaision to use his computers, it annoyed me.... (Read the rest)
Posted by: Gazok Posted on: 04/04/07 You are currently: Logged In as: a Guest  | Login | Terms of Use
is ALL security software flawed?  lutz.huesch@... | 02/08/07
*ALL* softare is flawed to some extent .....  bobjones68@... | 02/08/07
One more flawed than others ..  christian.wanscher@... | 02/09/07
Short answer is yes.  maldain | 02/12/07
Funny thing about anti-virus  NonZealot | 02/08/07
Agreed. Limited user accounts do more for security than AV does  PB_z | 02/08/07
Agreement :P  Okkio | 02/12/07
AV???  puppadave | 02/08/07
RE: AV????  chillintex | 02/10/07
Bogus!  thookerov | 02/10/07
More bogus  thookerov | 02/10/07
RE: More Bogus  Lynne's Honey | 02/10/07
av???  beermaster2003 | 02/12/07
Overflow of buffer flaw  a_gautier | 02/09/07
What's New  gordon_zigenbine@... | 02/09/07
Symantec AV always a problem  douglas_goodall | 02/09/07
Symantec, or user, defective?  LuckyCharm | 02/12/07
Trend Micro flaw  marty_mathieson@... | 02/09/07
Never had a problem with Trend  StephG72 | 02/12/07
I agree - Trend is better than most AV programs  jcitron@... | 02/12/07
Please don't lie or exagerate  Gray Eagle | 02/12/07
Depends on his connection...  Gazok | 02/13/07
re: Depends on his connection...  johnay | 02/15/07
I got rid of it.  G Fedorchuk | 02/09/07
Confused User  Gray Eagle | 02/12/07
SCAN ENGINE  BALTHOR | 02/12/07
Trend Micro flaw opens PCs to takeover  PhoenixStorm26 | 02/12/07
NOD32 Anti-Virus Protection System  orcan | 02/12/07
Screw thevirus makers and the antivirus suppliers...use LINUX  jackofalltradesmasterofnone | 02/12/07
An Overly Simple View!  Gray Eagle | 02/12/07
If we all used Linux...  Gazok | 02/13/07
Just be done with it and get a Mac or switch to LInux...  nix_hed | 02/13/07
Boo to Trend Micro!  Gazok | 02/13/07
Unhelpfull comments  Gray Eagle | 02/13/07
I don't even use them  Gazok | 04/04/07
Buffer overflow?  ttocsmij | 02/13/07
Can'r reach TrendMicro!  jerrybcampbell@... | 02/13/07
Trend Micro are definately still in business  Gray Eagle | 02/13/07
Surprised? This is ancient history!  bobinvegas@... | 02/13/07
Last word on stupid ranting and raving  Gray Eagle | 02/13/07
Last word on stupid ranting and raving  Gray Eagle | 02/13/07

What do you think?

advertisement
Click Here