Member Panel


Sponsors and Ads

Live Tag Cloud

PC Forum PC Help Forum » Security & Safety » Security Watch » Symantec Plugs 'High Risk' AV Engine Flaw.

Security Watch - Symantec Plugs 'High Risk' AV Engine Flaw. posted in the Security & Safety forums; Symantec Plugs 'High Risk' AV Engine Flaw . Anti-virus specialist Symantec Corp. has confirmed a high-risk vulnerability in multiple enterprise-facing products and warned that a successful exploit could lead to ...

JOIN US NOW to remove these Ads

pc help forum number one in the search engines
Post New Thread  Reply
  #1  
Old 10-08-2005
joe5's Avatar
Elite Member
My PC
 
Join Date: Jun 2005
Location: Netherlands
Posts: 9,044
joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page
Default Symantec Plugs 'High Risk' AV Engine Flaw.

Symantec Plugs 'High Risk' AV Engine Flaw .



Anti-virus specialist Symantec Corp. has confirmed a high-risk vulnerability in multiple enterprise-facing products and warned that a successful exploit could lead to code execution attacks.




The company released a security alert to acknowledge the flaw, which was flagged in the Symantec Antivirus Scan Engine: Web Service Administrative Interface.

"The remote exploitation of a buffer overflow vulnerability in the Web-based Administrative Interface of the Symantec AntiVirus Scan Engine could potentially allow remote attackers to execute arbitrary code on a targeted system," the company warned.

The vulnerability carries a "high risk" rating.

The vulnerability is due to insufficient validation of user input in HTTP requests passed to the Scan Engine Web Service. A malicious hacker with access to an exposed administrative port could supply a maliciously crafted HTTP request to launch harmful code.

"[This] could potentially result in the execution of arbitrary code and unauthorized privileged access to the targeted system," Symantec said.

Successful exploitation allows arbitrary code execution with SYSTEM privileges, but requires the ability to send HTTP requests to port 8004/tcp. Affected users could also be at risk of denial-of-service attacks.

The vulnerability has been confirmed in the Symantec AntiVirus Scan Engine (version 4.0 and 4.3) and several enterprise-facing products that use the scan engine.


Patches to correct the vulnerability have been posted online Here.

From:

http://www.eweek.com/article2/0,1895,1867475,00.asp


Comments on this post
ladygreenwitch agrees: Joe, you do such a great job of hunting all of this down to keep us all safe. Nice Job!!
__________________
- PCHF Team. - (NL) - Mal-ware Eradicator! -


Reply
New! Norton Internet Security 2008 – Download Now Click Here

Bookmarks

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are Off
Pingbacks are Off
Refbacks are On

Similar Threads
Thread Thread Starter Forum Replies Last Post
[Fixed] Hanging Programs Panache [Fixed] Hijackthis! Logs 60 09-06-2005 04:09 AM
[Fixed] Help Me Please Panache [Fixed] Hijackthis! Logs 20 08-06-2005 11:19 PM
[Pending] Help! Spy problem. Hijack this Log... APS71 [Fixed] Hijackthis! Logs 1 08-02-2005 07:51 PM


All times are GMT +1. The time now is 03:38 AM.
Powered by vBulletin
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
SEO by vBSEO 3.2.0 RC7
All Graphics & Content Copyright © 2004-2008 - PC Help Forum.com


Back to Top