Symantec vulnerability discovered - and fixed

Buffer overflow vulnerability found in corporate AV software.

Symantec was quick to respond late last month to the discovery of a potentially critical vulnerability in the latest versions of its corporate anti-virus software.

Advertise on www.virusbtn.com

The stack overflow vulnerability, which was discovered by researchers at eEye Digital Security in Symantec Client Security 3.x and Symantec AntiVirus Corporate Edition 10.x, would potentially allow remote attackers to execute code on the affected machine - without any user interaction.

Symantec responded to the discovery by releasing a series of intrusion prevention signatures for the affected versions of the software. The company was also quick to point out that it was not aware of any customers affected by the vulnerability, or of any exploits of the vulnerability.

01 June 2006

Tags:    del.icio.us  digg this! digg this

Quick Links



Poll

When do you install software updates?
As soon as they are released
As soon as I have some time
I take my time, but I always install them eventually
Only when I feel it is absolutely necessary
Never
Leave a comment
View 12 comments

Jobs Recruit Sidebar

Twitter Feed

virusbtn: RT @emailsecmatters: The typical spam message has sources as diverse as the spam lunch meat: http://ht.ly/2yucd
2 hours ago


virusbtn: Can anyone write a rap about our RAP tests (http://bit.ly/255ySQ) and submit it to the Symantec competition http://bit.ly/bOJg8r
6 hours ago


Malware Prevalence

Autorun |########|
Conficker/Downadup |######|
VB |#####|
Agent |#####|
FakeAlert/Renos |####|
 View this month's full report
Virus Bulletin currently has 208,232 registered users.