Flaw allows code to be executed on the target machine
Flaw allows code to be executed on the target machine
R E L A T E D   C O N T E N T
ADVERTISEMENT

McAfee flaw leaves users wide open

Antivirus library at risk

Iain Thomson, vnunet.com 18 Mar 2005
ADVERTISEMENT

Security research firm ISS has issued an advisory warning of a "serious flaw" in McAfee's antivirus library system that leaves users wide open to attack.

The flaw is in 23 versions of McAfee's products, and stems from a vulnerability in the antivirus library which the software uses to check for malware. ISS warned that ISPs, businesses and home users are all at risk.

"ISS has shipped protection for a flaw discovered by X-Force in McAfee AntiVirus Library versions prior to 4400," said the advisory.

"The Library is widely relied on to provide antivirus capabilities to desktop, server and gateway systems. Also, several large vendors and ISPs implement the Library in their products."

The flaw can be exploited if a hacker sends an email to the target with a specially crafted 'Lha' file, a type of format read by many software engines.

The user does not need to open anything; instead the file overwhelms the library's buffer and allows code to be executed on the target machine.

MacAfee was unavailable for comment. The ISS advisory can be seen here.

See also:

Tougher police tactics may have led to reduction in virus epidemicsBut every silver lining has a cloud  10 Mar 2005
Virus writers using spyware to generate revenueShow us the money  09 Mar 2005
SecurityThe latest wave of cyber-crimes and acts of vandalism have demonstrated once again that many systems are still vulnerable to attack.  15 Apr 2004

All Enterprise Security Technology

Like this story? Spread the news by clicking below:

Post this to Delicious del.icio.us    Post this to Digg Digg this    Post this to reddit reddit!

Permalink for this story

M A R K E T P L A C E
Sponsored links
F E A T U R E D   J O B S
| Abraxas
Join a leading provider of personal navigation products amp; value with navigation solutions currently used in 20 countries. You will join the eCommerce team within IT amp; continuity of eCommerce amp; security. Besides diving into ... more >
| Abraxas
Join a leading provider of personal navigation products amp; value with navigation solutions currently used in 20 countries. You will join the ICT department amp; resource plan aligned with project portfolio. Manage/ escalate issues amp; ... more >
| Abraxas
Join a leading provider of personal navigation products amp; value with navigation solutions currently used in 20 countries. You will join the eCommerce team within ICT as a Team Manager amp; reversed logistics domain, acting ... more >
| Abraxas
Join a successful global consumer electronics company as senior test engineer. You will pro-actively make contributions to the overall quality of the test documentation base amp; take the initiative in implementing such improvements. You will ... more >
More job opportunities