Welcome Guest. | Log In| Register | Membership Benefits
  • Email this page E-mail this page
  • |  Print Print this page
  • |   Bookmark and Share

Symantec Vulnerability Revealed

EEye Digital Security uncovers remotely exploitable vulnerability in Symantec anti-virus program

May 25, 2006 | 08:25 AM

By Mike Fratto
DarkReading

EEye Digital Security revealed this afternoon a software vulnerability inside Symantec's Anti-Virus Corporate Edition 10.0.

The vulnerability warning, posted on the vendor's Upcoming Advisories page, requires no user intervention and could be used to create a worm. A Symantec representative told Dark Reading that eEye notified Symantec of the problem today and it is investigating the issue.

Marc Maiffret, eEye's co-founder and chief hacking officer, said, "Symantec hasn't gotten back to us with a timeline yet, but they are very responsive to vulnerability reporting and quickly fix problems compared to other vendors we work with, like Microsoft."

EEye also tested Symantec's consumer security suite, Norton Internet Security 2006, which eEye uses, and found that it was not vulnerable. "We don't know how many other Symantec products are affected because of bundling," Maiffret said. "But with Symantec's large deployment footprint, a worm could spread fast."

Since the problem affects Symantec's Corporate Edition and is remotely exploitable, some experts deduced that the problem may lie with the software that handles centralized management. However, this could not be confirmed with eEye or Symantec.

According to eEye, its researchers were working to integrate its host protection product, Blink, with Anti-Virus Corporate Edition and decided to test the application. To eEye's surprise, it took little more than a week to find the vulnerability and create a working exploit.

Maiffret thinks the ease and speed of finding an exploitable bug may indicate development problems in Symantec. "Finding exploitable bugs in security software is bad enough, but finding generic problems like stack-based buffer overflow indicates systemic issues. Using secure development practices is costly for small developers, but a billion-dollar company like Symantec can afford it."

— Mike Fratto, Editor at Large, Dark Reading

Organizations mentioned in this story:

  • eEye Digital Security
  • Symantec Corp. (Nasdaq: SYMC)


  • Subscribe to RSS










    Bugs
    ENTERPRISE VULNERABILITIES
    Vulnerability:suse linux
    Published:2010-01-22
    Severity:High
    Description:SUSE Linux Enterprise 10 SP3 (SLE10-SP3) configures postfix to listen on all network interfaces, which might allow remote attackers to bypass intended access restrictions.
    Vulnerability:ie
    Published:2010-01-22
    Severity:High
    Description:The URL validation functionality in Microsoft Internet Explorer 7 and 8 does not properly process input parameters, which allows remote attackers to execute arbitrary local programs via a crafted URL, aka "URL Validation Vulnerability."
    Vulnerability:bind
    Published:2010-01-22
    Severity:Medium
    Description:ISC BIND 9.0.x through 9.3.x, 9.4 before 9.4.3-P5, 9.5 before 9.5.2-P2, 9.6 before 9.6.1-P3, and 9.7.0 beta does not properly validate DNSSEC (1) NSEC and (2) NSEC3 records, which allows remote attackers to add the Authenticated Data (AD) flag to a forged NXDOMAIN response for an existing domain.
    Vulnerability:ie
    Published:2010-01-22
    Severity:High
    Description:Microsoft Internet Explorer 6, 6 SP1, 7, and 8 does not properly handle objects in memory, which allows remote attackers to execute arbitrary code by accessing an object that (1) was not properly initialized or (2) is deleted, leading to memory corruption, aka "Uninitialized Memory Corruption Vulnerability," a different vulnerability than CVE-2009-2530 and CVE-2009-2531.
    Vulnerability:ie
    Published:2010-01-22
    Severity:High
    Description:Microsoft Internet Explorer 8 does not properly handle objects in memory, which allows remote attackers to execute arbitrary code by accessing an object that (1) was not properly initialized or (2) is deleted, leading to memory corruption, aka "Uninitialized Memory Corruption Vulnerability," a different vulnerability than CVE-2009-3671, CVE-2009-3674, and CVE-2010-0246.


    Briefing Centers
    POWERFUL INFORMATION
    AT YOUR FINGERTIPS
    (SPONSORED LINKS)