F-Secure Quickly Fixes 23 Flaws In Its Anti-Virus Products
The flaws in its flagship Windows and Linux anti-virus line were revealed by an independent researcher.
Finnish security company F-Secure released patches for its flagship Windows and Linux anti-virus line Thursday to fix flaws revealed by an independent researcher.
The bugs in 23 editions of F-Secure Anti-Virus, Internet Gatekeeper, and Internet Security affect how it parses .zip and .rar compressed files, according to the researcher, Thierry Zoller, who works for an unnamed Luxembourg security firm.
Maliciously crafted .zip files can be used to create a buffer overflow on PCs defended with F-Secure titles; after that, hackers could load their own code onto the compromised machine. A second flaw can be exploited with specially made .zip or .rar files to hide malicious code from the anti-virus scanning engine, giving users a false sense of security and attackers a way to sneak stuff past protection.
F-Secure dubbed the flaws "Critical," and rolled out fixes Thursday. Patches can be downloaded from the Helsinki-based company's FTP servers. (F-Secure Anti-Virus 2004/2005/2006, Internet Security 2004/2005/2006, and Personal Express 6.2 and earlier will automatically retrieve the fixes.)
"Our guidance is the same as for patches from any other vendor: Patch now before someone figures out how to exploit the vulnerability," F-Secure's director of anti-virus research, Mikko Hypponen, wrote on the company's Web site. "At the moment we are not aware of any attacks that would have used this vulnerability."
5 Top Federal Initiatives For 2015As InformationWeek Government readers were busy firming up their fiscal year 2015 budgets, we asked them to rate more than 30 IT initiatives in terms of importance and current leadership focus. No surprise, among more than 30 options, security is No. 1. After that, things get less predictable.
InformationWeek Tech Digest, Nov. 10, 2014Just 30% of respondents to our new survey say their companies are very or extremely effective at identifying critical data and analyzing it to make decisions, down from 42% in 2013. What gives?