Symantec vulnerabilities

eEye reports four new Symantec vulnerabilities

eEye Digital Security has reported that it has discovered four new vulnerabilities affecting Symantec products. Products affected are Norton Internet Security 2004, Norton Internet Security 2004 Professional and Norton Personal Firewall 2004.

Advertise on www.virusbtn.com

eEye rates the severity of all four vulnerabilities as 'high' and describes three of them as 'remotely-exploitable vulnerabilit[ies] that allow anonymous attackers to compromise default installations of the affected software and gain absolute access to the host machine' and the fourth as 'a remotely-exploitable vulnerability that allows an anonymous attacker to execute a severe denial-of-service attack against systems running default installations of the affected software.' Another Symantec vulnerability is currently awaiting the release of a patch.

eEye employs a policy of releasing only minimal details of vulnerabilities until the manufacturer of the software concerned has released a patch. Nevertheless, March 2004 saw a buffer overflow vulnerability employed by a worm only 24 hours after its publication by eEye - see VB May 2004, p.9.

20 April 2004

Tags: virus  

 del.icio.us  digg this! digg this

Quick Links

Poll
Does your company allow you to use a personal laptop/mobile device to access company resources?
Yes, it's allowed
Yes, it's actively encouraged
No
I don't know
Leave a comment
View 1 comment

EC-council-boston

VB100 certification
VB100 As expected, the annual VB100 test on Windows XP was an epic. A higher than usual pass rate was tempered by numerous stability issues with the products under test, prompting the unveiling of a new stability rating system. John Hawes has all the details.
See full results.

Virus Bulletin currently has 225,189 registered users.