• On GameSpot: Wii Fit tells 10-year-old she's fat

May 30, 2006 3:01 PM PDT

Symantec patches antivirus worm hole

  • Print
Symantec over the weekend delivered fixes for a high-profile flaw in its corporate antivirus products that could be exploited in an Internet worm attack.

Users of Symantec AntiVirus Corporate Edition and Symantec Client Security should apply the appropriate update as soon as possible, Vincent Weafer, a senior director at Symantec Security Response, said Tuesday. However, because there are no known attacks that exploit the flaw, the need to patch is not urgent, he added.

The vulnerability was initially reported last week by eEye Digital Security. The flaw, a remotely exploitable buffer overflow, could potentially allow an attacker to run malicious code on a vulnerable computer. Because Symantec's software is so widely used, this could cause havoc on the Internet--for example, if a worm were to exploit the problem.

Got views on Vista?

Recognizing the urgency to deliver a fix, Symantec worked over the weekend--a holiday weekend in the U.S.--to deliver patches. "Since it was publicly reported, we did have to go into emergency mode and deliver patches for the products," Weafer said.

Ubiquitous antivirus software is like low-hanging fruit to hackers, analysts have said. As the pool of easily exploitable Microsoft Windows bugs dries up, attackers are looking for holes in security software to break into PCs. Symantec realizes this, Weafer said.

"More eyes are looking for these vulnerabilities," he said. "This is clearly something we're going to look at ourselves. We can use this as a lesson to determine if there is any change needed to our secure programming."

Symantec has fixes available for the English versions of its products. The Cupertino, Calif., company is still working on updates for international versions. The products affected by this security issue are Symantec AntiVirus Corporate Edition version 10.x and Symantec Client Security version 3.x.

See more CNET content tagged:
Symantec Corp., Symantec AntiVirus, antivirus, fix, flaw

Add a Comment (Log in or register) 1 comment
am i reading this correctly?
by stollerby May 31, 2006 12:01 AM PDT
what? no known attacks that exploit the flaw & the need to patch is not urgent?

Somebody please give Vincent Weafer some lessons in PR.

it's expected that the company i'd pay for software security would be on their toes and taking care of any concerns irregardless if it's immediate or not.

Luckily, Symantec hasn't felt what Sony is feeling right now (yet). Hit the panic button when necessary. It's a sunny summer now.
Reply to this comment
advertisement

Latest tech news headlines

RSS Feeds

Add headlines from CNET News to your homepage or feedreader.

More feeds available in our RSS feed index.

Markets

Market news, charts, SEC filings, and more

Related quotes

Symantec (4.51%) 0.50 11.59
Dow Jones Industrials (3.31%) 270.00 8,419.09
S&P 500 (3.99%) 32.60 848.81
NASDAQ (3.70%) 51.73 1,449.80
CNET TECH (3.64%) 36.93 1,051.13
  Symbol Lookup
advertisement

Inside CNET News

Scroll Left Scroll Right