Channel News and Analysis - Channel Insider
Empowering the next generation Channel
 

Sponsored Links
  • Get up and running in as quickly as 30 days with BI. Learn how today.
  • FREE Securing Smartphones & Tablets for Dummies Book from Sophos
  • 5 New Technologies That Will Change Enterprise ITAdvertisement
  • Build an IT Infrastructure That Delivers the Future

  •  

    Symantec Patches High-Risk Vulnerability

    in Channel News and Analysis



    Article Rating:starstarstarstarstar / 0
    Article Views: 2047

    Symantec discontinues the use of the DEC2EXE parsing engine to address a highly critical flaw affecting multiple product lines.

    Rate This Article:
    Add This Article To:

    Network security specialist Symantec Corp. has confirmed a high-risk vulnerability in multiple anti-virus and anti-spam products and warned that a successful exploit could lead to code execution attacks.

    The vulnerability, which was reported by Internet Security Systems Inc.'s X-Force unit, is described as a boundary error in the DEC2EXE parsing engine used in versions of the Symantec scan engine.

    "The vulnerable DEC2EXE engine contained a heap overflow that could be initiated by sending a specifically crafted UPX file that would be parsed by the vulnerable DEC2EXE engine. If successfully exploited, the attack could potentially result in remote arbitrary code execution and possible compromise of the targeted system," Symantec said in a security advisory.

    In response, the Cupertino, Calif.-based company has discontinued use of the DEC2EXE engine, which is no longer required to parse compressed files. Symantec officials said the company had already deleted the vulnerable engine from the majority of its products and had planned to complete the removal from all affected product lines during upcoming maintenance updates.

    A separate alert from ISS X-Force said the flaw affects all products that depend on the Symantec AntiVirus Library to push out anti-virus capabilities to desktops, servers and enterprise gateway systems.

    "Several large vendors and ISPs implement Symantec's AntiVirus Library in their products. By crafting a UPX file, an attacker is able to trigger a heap overflow within the process importing the Symantec AntiVirus Library," ISS X-Force said in the alert.

    The flaw affects multiple enterprise and consumer product lines, ranging from Norton AntiVirus, Symantec Mail Security, AntiVirus/Filtering, Symantec Web Security, Symantec BrightMail AntiSpam and Symantec AntiVirus Corporate Edition.

    Click here to read about high-risk security holes in Symantec's Nexland Firewall appliances.

    The company has published a complete list of affected and non-affected products.

    Symantec has also posted hotfixes to address this issue for the affected Symantec Gateway Security 5300 and 5400 Series appliances. The fix removes the legacy DEC2EXE engine from the affected products and upgrades the scan engine to a new version.

    Product specific hotfixes are available through the Symantec Enterprise Support site.

    Check out eWEEK.com's for the latest security news, reviews and analysis. And for insights on security coverage around the Web, take a look at eWEEK.com Security Center Editor Larry Seltzer's Weblog.




    comments dic


     
     
    >>> More Channel News and Analysis Articles          >>> More By Ryan Naraine
     


     



    channel chatter


    HTML PLAIN TEXT

    Keep on top of news for VARs and Resellers with CI's Weekly Newsletter and Alerts.


    [ci] feeds
    XML
    Add Channel News, Product Reviews, Trends and Analysis to your RSS newsreader or My Yahoo!


     


    CHANNEL SPONSORED RESOURCE CENTER
     
     
     
    Start the New Year with business intelligence—it’s a smart move
    Join us on February 1 for an encore rebroadcast at either 5 am or 12 noon EST and discover how business intelligence (BI) supports companies in uncertain business and economic climates. Get expert advice on how to create a strategy that fits your organization's needs and budget and see how quickly it can pay for itself.
    Click Here
     
    Security and Availability Essentials for Running Your Business in the Cloud
    Are you moving to the cloud? Find out what every IT professional should know about security and availability before moving to the cloud. Hear what a security provider’s own CSO has to say.
    Watch Video
    A new algorithm automatically identifies relationships between variables to help reduce researcher prejudice.
    Click HereAdvertisement