Symantec Bug Not Likely To Be Hit By Worm, Says Rival - InformationWeek
IoT
IoT
News
News
12/23/2005
01:09 PM
50%
50%
RELATED EVENTS
Building Security for the IoT
Nov 09, 2017
In this webcast, experts discuss the most effective approaches to securing Internet-enabled system ...Read More>>

Symantec Bug Not Likely To Be Hit By Worm, Says Rival

Internet Security Systems said in an online alert that although the vulnerability is serious, the likelihood of the flaw being leveraged by a worm is "low."

The vulnerability in Symantec's anti-virus line disclosed earlier this week isn't a big risk, a rival security firm said Friday.

Internet Security Systems' X-force research group said in an online alert that although the vulnerability is serious, the "likelihood of this vulnerability being leveraged by a worm is low."

The bug in Symantec's AntiVirus Library, a component shared among more than 60 titles in the Cupertino, Calif.-based company's security line-up, was made public earlier this week. The Library can be compromised by sending a malicious RAR archive file as an e-mail attachment, which then creates a heap overflow on the victimized PC or Mac. That condition could allow the attacker to introduce his own code remotely, without any user interaction.

Internet Security System (ISS), however, noted that a successful exploitation of the flaw requires a very large RAR file, one in the 35-40MB range.

"Files this large are not generally passed by mail servers and [so we] can eliminate this as a vector for a worm," continued the ISS alert.

Symantec has pushed out an update that should spot any attempt to exploit the bug, but it has not yet produced patches to fix the underlying flaw.

Comment  | 
Print  | 
More Insights
Comments
Newest First  |  Oldest First  |  Threaded View
How Enterprises Are Attacking the IT Security Enterprise
How Enterprises Are Attacking the IT Security Enterprise
To learn more about what organizations are doing to tackle attacks and threats we surveyed a group of 300 IT and infosec professionals to find out what their biggest IT security challenges are and what they're doing to defend against today's threats. Download the report to see what they're saying.
Register for InformationWeek Newsletters
White Papers
Current Issue
Digital Transformation Myths & Truths
Transformation is on every IT organization's to-do list, but effectively transforming IT means a major shift in technology as well as business models and culture. In this IT Trend Report, we examine some of the misconceptions of digital transformation and look at steps you can take to succeed technically and culturally.
Video
Slideshows
Twitter Feed
Sponsored Live Streaming Video
Everything You've Been Told About Mobility Is Wrong
Attend this video symposium with Sean Wisdom, Global Director of Mobility Solutions, and learn about how you can harness powerful new products to mobilize your business potential.
Flash Poll