On CNET: Think you know Apple history
BNET Business Network:
BNET
TechRepublic
ZDNet

By Matt Hines
Posted on ZDNet News: Mar 30, 2005 4:47:00 PM

Symantec has reported glitches in its antivirus software that could allow hackers to launch denial-of-service attacks on computers running the applications.

In a notice posted on its Web site this week, Symantec detailed two similar vulnerabilities found in its Norton AntiVirus software, which is sold on its own or bundled in Norton Internet Security and Norton System Works. The flaws, which could lead to computers crashing or slowing severely if attacked, are limited to versions of the software released for 2004 and 2005.

The Information-Technology Promotion Agency of Japan, a government-affiliated tech watchdog group, identified the first instance of the problem in the AutoProtect feature of the Norton AntiVirus consumer product, Symantec said. AutoProtect is used to scan files for viruses, Trojan attacks and worms.

The flaw essentially causes Symantec's software to crash when it is asked to inspect a file specifically designed to exploit the flaw. The file could be submitted either remotely from outside a system or internally by someone with physical access to a computer, Symantec said.

The second flaw, discovered by the Japan Computer Emergency Response team, can be used to launch denial-of-service attacks by scanning specific file modifications using the SmartScan feature in Norton AntiVirus. Symantec said that any malicious use of that vulnerability would specifically require someone with authorized access to a computer to exploit the issue. SmartScan is designed to scour for viruses hidden in file extensions, as well as in executable and document files.

No attacks related to either problem have been reported so far, according to Symantec. The company also said in its warning that both vulnerabilities are "low impact" threats to its customers.

Cupertino, Calif.-based Symantec said it has informed its customers of the problems and has issued patches to correct the flaws, including sending out an automated fix to subscribers to its Automatic LiveUpdate service. The company recommended that people who have not already applied the patches do so immediately to protect against potential attacks.

  • Talkback
  • Most Recent of 29 Talkback(s)
Norton/Symantec has worked for me
I have used Norton Corporate Anti-Virus and Symantec Corporate Anti-Virus since version 7.5. I heave had very few problems. The only problems I have had is with a few old Win98 computers who's users h... (Read the rest)
Posted by: dkroger@stratagraph.com Posted on: 09/02/05 You are currently: Logged In as: a Guest  | Login | Terms of Use
First Fix Your Own House  Techscan | 03/30/05
The Tom DeLay School of Media Manipulation (nt)  Judas I. | 03/30/05
Local Access?  rpmyers1 | 03/30/05
Wow, my old Norton would be great  FilledOut | 03/30/05
"Symantec has reported glitches in its antivirus software"  KOS-MOS | 03/30/05
Very Unlikely...  DarbyOhara | 03/31/05
Protect yourself with a Virtual PC  alterego_z | 03/30/05
Imagine that!  bony tryan | 03/30/05
Depends on what "remotely" means  rpmyers1 | 03/30/05
Deep Incompetence  michael-t | 03/30/05
Fed up of having to re-install  grandad_z | 03/30/05
re: Fed up of having to re-install  Wolfie2K3 | 03/30/05
major flaws in Symantec software for 3 yrs  gilde | 03/30/05
AVG  miked@... | 03/31/05
Norton Sucks  bammike | 03/31/05
Yes it does!  Fizban | 03/31/05
My next AV will not be Norton  jpr75_z | 03/31/05
Symantic Software  hinm@... | 03/31/05
2005 was not out 2 years ago  grandad_z | 03/31/05
Norton Antivirus and SystemWorks 2005 On Its 3rd Installation!  Automate | 05/28/05
software testing is a continual necessity. just ask M$ how they debug their  wessonjoe | 03/31/05
Symantec lies and manipulation  Im1CrazyCow | 03/31/05
You do back up your work?  osreinstall | 03/31/05
Symeantec= no problems for me  AZR | 04/04/05
Symantec = No Problems?  SeenITAll | 07/27/05
Symantec=No problems for me=head in sand  rmerts@... | 07/27/05
I agree  jkozura_z | 07/27/05
new vulnerabilities in AV Software  pthomassr | 06/24/05
Norton/Symantec has worked for me  dkroger@... | 09/02/05

What do you think?

CIO Sessions

advertisement
Click Here