Skip Links

Network World

  • Social Web 
  • Email 
  • Close

(Comma separation for multiple addresses)
Your Message:

Symantec AntiVirus Scan Engine has serious bug

By Robert McMillan , IDG News Service , 10/06/2005
  • Share/Email
  • Tweet This
  • Comment
  • Print

Users of the Symantec 's AntiVirus Scan Engine are being advised to upgrade their software, thanks to a critical security bug in the product. The flaw could theoretically allow an attacker to take control of an affected system, according to Symantec.

Because of a bug in the Scan Engine's administrative interface, it is possible for an attacker to take over a system running the software by creating a specially crafted HTTP request, Symantec said in a security advisory . The attacker would need to gain access to an exposed administrative port on the server for this attack, the report said.

Users of versions 4.0 and 4.3 of the Scan Engine product are advised to upgrade to version 4.3.12, Symantec said.

Symantec is the second security vendor to report a major security bug in its products this week. Kaspersky Labs also reported a similarly critical flaw in its Antivirus Library, which is used by a wide range of the company's anti-virus products.

 

  • Share/Email
  • Tweet This
  • Comment
  • Print

Comment
Login
Forgot your account info?
Add comment
Anonymous comments subject to approval. Register here for member benefits.
Have a NetworkWorld account? Log in here. Register now for a free account.

Videos

rssRss Feed