Flaw allows code to be executed on the target machine
Flaw allows code to be executed on the target machine
R E L A T E D   C O N T E N T
ADVERTISEMENT

McAfee flaw leaves users wide open

Antivirus library at risk

Iain Thomson, vnunet.com 18 Mar 2005
ADVERTISEMENT

Security research firm ISS has issued an advisory warning of a "serious flaw" in McAfee's antivirus library system that leaves users wide open to attack.

The flaw is in 23 versions of McAfee's products, and stems from a vulnerability in the antivirus library which the software uses to check for malware. ISS warned that ISPs, businesses and home users are all at risk.

"ISS has shipped protection for a flaw discovered by X-Force in McAfee AntiVirus Library versions prior to 4400," said the advisory.

"The Library is widely relied on to provide antivirus capabilities to desktop, server and gateway systems. Also, several large vendors and ISPs implement the Library in their products."

The flaw can be exploited if a hacker sends an email to the target with a specially crafted 'Lha' file, a type of format read by many software engines.

The user does not need to open anything; instead the file overwhelms the library's buffer and allows code to be executed on the target machine.

MacAfee was unavailable for comment. The ISS advisory can be seen here.

See also:

Tougher police tactics may have led to reduction in virus epidemicsBut every silver lining has a cloud  10 Mar 2005
Virus writers using spyware to generate revenueShow us the money  09 Mar 2005
SecurityThe latest wave of cyber-crimes and acts of vandalism have demonstrated once again that many systems are still vulnerable to attack.  15 Apr 2004

All Enterprise Security Technology

Like this story? Spread the news by clicking below:

Post this to Delicious del.icio.us    Post this to Digg Digg this    Post this to reddit reddit!

Permalink for this story
R E A D E R   C O M M E N T S

M A R K E T P L A C E
Sponsored links
F E A T U R E D   J O B S
Reading, Berkshire, United Kingdom | EDS
Technical Hosting Engineer Location - Reading Job Description: This is an applications infrastructure and engineering role within the team. This role is primarily focussed on developing and evolving a quarantine application hosting service. The quarantine ... more >
Hook, Hampshire, United Kingdom | EDS
Description: This vacancy is for an information security consultant to join EDS' Information Assurance team based in Hook. The successful applicant will provide information security support to one or more of EDS' major Defence projects. ... more >
London, United Kingdom | Royal Borough of Kensington and Chelsea
Web Content Manager - c.£40,000 plus bonus - London   As one of the country's best-performing councils, we're always looking for new ways to improve on excellence. Providing an innovative, high-quality internet site for our ... more >
Central London, United Kingdom | MI5 Security Services
Messaging System Engineer - Competitive salaries + excellent benefits - Central London Getting the best out of technology is critical to helping us protect the UK. Join MI5 and use your skills and experience to help ... more >
More job opportunities