Symantec software open to denial of service attacks
By Barry Collins
Posted on 29 Feb 2008 at 09:48
Symantec has admitted that certain versions of its security software are susceptible to denial of service attacks.
Products such as Symantec AntiVirus for Network Attached Storage and Mail Security for Microsoft Exchange contain an error with the Decomposer engine (the software that uncompresses files), which could result in malicious code causing systems to crash.
"The first issue is triggered when it receives malicious content," reads an advisory on Symantec's website. "If sufficiently malformed, this could possibly cause large amounts of memory to be consumed which could result in a Denial of Service.
"The second issue is a buffer overflow that can cause the decomposer to crash causing a Denial of Service condition and the potential for remote code execution."
The company says it has solved the problem and advises IT managers to update their software to the latest version to ensure they are not affected. Customers running the LiveUpdate service will have already received the patch.
"Symantec is not aware of any customers impacted by this issue, or of any attempts to exploit the issue," the advisory claims.
From around the web
advertisement
- Chrome's shine getting lost in translation
- BytePac: the cardboard hard disk enclosure
- How tech loosens our grip on reality
- Hokum watch: Safer Internet Day
- Why I'm deleting Adobe from my PC
- Prepare to be patronised: it's Safer Internet Day
- Dear Sony, Samsung and every other tech company in the world: stop trying to be Apple
- Will Apple's Final Cut Pro X update placate the pros?
- Smartr Contacts for iPhone review
- Switching to Office 365's Outlook Web App
- Why virtualisation hasn't slowed the growth of data
- How to make Google AdWords work for your business
- The curse of sloppily written software
- Paying for your crimes with Bitcoin
- Behind the scenes: tech support for Formula 1
- The security risk of fat fingers
- Why Windows Phone 7 isn't quite ready for business
- When will Microsoft stop fiddling with Windows 8?
- Flash down the pan?
- Metro Style apps vs desktop applications
advertisement
