Welcome to Full-Downloads Software Downloads Free Uk Software Download Mil Descargas.com - El mayor archivo de programas
Hello Anonymous! register?
Menu
  Home (News):
· Home
· Send News
· AvantGo
· Stories Archive
· Topics

Downloads:
· Downloads I
· Downloads II
 Comunity:
· Forums FP
· Web Links
· Members List
· Recommend Us
· Surveys
· Feedback
· ProgramasFull

 Users:
· Your Account
· Webmail
· Add Download

Statistics:
· Statistics
· Top
Top Stories
· W32/Bropia Worm spreading through MSN Messenger
· Tag your email to Passport.NET / MSN7 launch
· Symantec Products Hit By Major Security Bug
· The Future of Movie Downloads
· Nero Burning ROM 5.5.9.17
· BDE/B3D Killer v1.6 released
· Microsoft Plan Bold New PC Features With Longhorn
· China Cracks Down on Internet Cafes
· Microsoft & Nokia Collaborate on Digital Music
· W32/Bropia Worm spreading through MSN Messenger
User Online
There are currently, 9 guest(s) and 0 member(s) that are online.

You are Anonymous user. You can register for free by clicking here
Cat Downloads
 Audio & Video
· All-in-One Jukeboxes
· Audio Production
· CD & DVD Burners

 Design & Photo
· 3D Modeling & CAD
· Animation
· Authoring Tools

 Games
· Action
· Adventure
· Arcade

 Internet
· Tools & Utilities

 Software Developer
· ActiveX
· Compilers & Interpreters
· Components & Libraries

 Web Developer
· PHP
· Reference & Tutorials
· ASP

 Business
· Desktop Publishing
· Online Auctions

 Desktop Enhancements
· Cursors
· Icon Tools
· Icons

 Home & Education
· Language
· Calendars & Planners
· E-books & Literature

 IS/IT

 Utilities & Drivers
· Drivers
· File & Disk Management
: Symantec Products Hit By Major Security Bug
Posted on Monday, February 14 @ 11:02:08 ART by Webmaster
The General News the vulnerability is caused due to a boundary error in the DEC2EXE parsing engine used by the antivirus scanning functionality when processing UPX compressed files. This can be exploited to cause a heap-based buffer overflow via a specially crafted UPX file". In an advisory issued earlier this week, Symantec said that "The impact of this vulnerability is exaggerated by the fact that many e-mail and other traffic routing gateways make use of file-scanning utilities that make use of the vulnerable library. This could allow an attacker to potentially exploit high-profile systems used to filter malicious data, and potentially allow further compromise of targeted internal networks". The flaw affects as many as 30 Symantec products, almost all of the company's software. The company said that users of the most recent versions of its software, like Norton Antivirus 2005, were un-affected. The company added that "The DEC2EXE engine is no longer required to parse compressed files" and that "Symantec had planned the DEC2EXE engine removal from all affected Symantec product versions during upcoming maintenance update." However, it advised all users to ensure they were fully patched (see link below). The company is also distributing patches to users via its automated Live Update feature. View: Patch Up @ Symantec.com | Affected Products | Secunia AdvisoryRead full story...

A serious flaw in a comment element to Symantec's products has emerged this week; the company reported that the flaw was 'high' risk. Symantec, maker of protection software, said the flaw was in the antivirus library used in some of its products. Secunia elaborated on this further, saying that 'the vulnerability is caused due to a boundary error in the DEC2EXE parsing engine used by the antivirus scanning functionality when processing UPX compressed files. This can be exploited to cause a heap-based buffer overflow via a specially crafted UPX file'.

In an advisory issued earlier this week, Symantec said that 'The impact of this vulnerability is exaggerated by the fact that many e-mail and other traffic routing gateways make use of file-scanning utilities that make use of the vulnerable library. This could allow an attacker to potentially exploit high-profile systems used to filter malicious data, and potentially allow further compromise of targeted internal networks'.

The flaw affects as many as 30 Symantec products, almost all of the company's software. The company said that users of the most recent versions of its software, like Norton Antivirus 2005, were un-affected. The company added that 'The DEC2EXE engine is no longer required to parse compressed files' and that 'Symantec had planned the DEC2EXE engine removal from all affected Symantec product versions during upcoming maintenance update.' However, it advised all users to ensure they were fully patched (see link below). The company is also distributing patches to users via its automated Live Update feature.

View: Patch Up @ Symantec.com | Affected Products | Secunia Advisory






Source: Neowin.net

 
Related Links
· More about The General News
· News by Webmaster


Most read story about The General News:
W32/Bropia Worm spreading through MSN Messenger

Article Rating
Average Score: 0
Votes: 0

Please take a second and vote for this article:

Excellent
Very Good
Good
Regular
Bad


Options

 Printer Friendly Page  Printer Friendly Page

 Send to a Friend  Send to a Friend

Threshold
The comments are owned by the poster. We aren't responsible for their content.

No Comments Allowed for Anonymous, please register

Web site engine's code is Copyright © 2003 by PHP-Nuke. All Rights Reserved. PHP-Nuke is Free Software released under the GNU/GPL license.
Page Generation: 0.273 Seconds