Site Statistics
 
Threads: 3,718
Posts: 16,702
Members: 2,844
Users Online: 12
Newest Member: Boydaysop


Go Back   PC101 > PC Software > PC Security

PC Security Stop Spyware, Hackers and Identity thieves. Info re: Viruses, trojans, removal, etc...

Reply
 
LinkBack Thread Tools Display Modes
Old 04-17-2006, 02:41 PM   #1
aleeonline
Member
 
Join Date: Apr 2006
Posts: 79
Rep Power: 3 aleeonline is on a distinguished road
'High Risk' Flaw in Symantec AntiVirus Library

An independent security researcher on Tuesday flagged an unpatched flaw in the Symantec AntiVirus Library and warned that attackers could exploit the bug to execute arbitrary code when a malicious RAR archive is scanned.

In a published advisory, here in PDF form, researcher Alex Wheeler said the vulnerability is the result of unchecked 16-bit length fields in RAR sub-block header types.

An attacker may craft a sub-block header to overwrite heap memory with user controlled file data to execute arbitrary code. Successful attack will yield system/root-level privileges and is available through e-mail without user interaction, Wheeler said.

The RAR file format is widely used for data compression and archiving and is popular among users looking to compress very large music and video files.

read more
aleeonline is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
Reply


Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On


Similar Threads
Thread Thread Starter Forum Replies Last Post
New 'botworm' exploits Symantec flaw Lyte PC Security 0 12-17-2006 04:54 PM
Symantec Norton AntiVirus 2001 raju79 Windows Vista, XP, 2000, 98, etc... 1 07-10-2006 02:02 PM
eEye Reports Dangerous Vulnerability in Symantec Anti-Virus Will.Spencer PC Security 0 05-26-2006 07:11 PM
Symantec Antivirus Scan Engine Buffer Overflow aleeonline PC Security 0 04-17-2006 02:48 PM



Flex Development


Our partners:



All times are GMT -5. The time now is 10:25 PM.

Powered by vBulletin Version 3.6.7
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
Search Engine Optimization by vBSEO 3.0.0
Design by vBSkinworks

Copyright © PC101 and PC101.com Computer Forum. All rights reserved.