Newsletter

Newsletter TechSpot Poll

Get weekly updates on new articles, news and contests in your mail!

Email address:

IT

Symantec patches anti-virus vulnerability

By Derek Sooman, TechSpot.com
Published: May 29, 2006, 4:27 AM EST

Symantec has posted a fix for a vulnerability in their Antivirus Corporate Edition and Client Security products that could have allowed remote users to launch worm attacks. The issues of remote code execution have been resolved now, thanks to the fix which means that the products are no longer vulnerable to a stack overflow. The flaw, which doesn't require any user interaction in order to be exploited, was pretty serious as it impacted enterprise-level customers. A worm crafted to take advantage of the exploit could have had a disastrous impact, particularly on large companies that use the affected software. The flaw was discovered by digital security firm the eEye, who rated the flaw as highly severe.

"As a trend, we are seeing the complexity of software increase and as a result the existence of vulnerabilities is pretty prevalent at the application layer," the eEye spokesperson said. "Anytime you have complex software there are going to be vulnerabilities."

Related Stories

User Comments (2)

Post a comment
canadian
on May 29, 2006
9:12 AM
Wow, that was a fast fix.

Phantasm66
on May 29, 2006
9:37 AM
Of course it was - they are providing a security product and to be the cause of a high critical flaw is a total embarrasement. I'm surprised it was not even quicker. If you were Symantec, when it came to finding the solution for that money would be no obstacle.

Browse more commented news