Another antivirus software flaw detected

For the fifth time in two months, security researchers have publicised a serious flaw in a widely used virus-scanning program.

The vulnerability affects McAfee's Antivirus Library, a collection of common code shared among the security software company's various virus scanners, including GroupShield for mail servers and VirusScan for PCs. An attacker could use the flaw to cause a vulnerable system to run a file instead of scanning it for malicious code.

While the company just learned of the issue recently, an update offered to corporate customers in November and consumers in December added security measures that fixed the problem.

"Once the update was released, all current subscribers got the fix," said Mark Solomon, senior product manager for McAfee. "For anyone who is no longer a subscriber, this is a reminder to renew."

The flaw is the fourth antivirus security vulnerability found by Internet Security Systems, which sells software and hardware to protect networks and corporate PCs. The company also has found flaws in the antivirus libraries developed by security software companies Symantec, F-Secure and Trend Micro. Another flaw in Computer Associates International's antivirus software was discovered by security firm eEye Digital Security.

Internet Security Systems would not specify how the problems were found, but a representative stressed that the company didn't target the products.

Users of McAfee's virus scanning software, also known as an engine, are vulnerable only if the software has not been updated through a current subscription and the person has not downloaded the latest virus definitions file, or DAT, from the company.

The flaw could be exploited using any type of network traffic that is scanned by a McAfee product, including e-mail, Web browsing and Windows file sharing. When the vulnerable software attempted to open a malicious file, the software would instead run the program included in the file.

Advertisement

Talkback 0 comments

Latest Videos

Sponsored content

Power Centre - Content from our premier sponsors

Blogs

  • David Braue Can not-so-smart meters help the NBN?
    It was interesting to witness Conroy's recent enthusiasm to spruik the NBN's role in supporting the Smart Grid, Smart City initiative. What a pity that Conroy hadn't yet seen the damning report from the Victorian auditor-general about that state's smart-meter roll-out.
  • Array Can the Telco Reform Act be win-win?
    In the second of our two programs looking at the Senate Inquiry into the Telecommunications Legislation Amendment Bill, we hear from shareholders, bureaucrats and industry groups.
  • Array Has New Zealand's smiling assassin delivered?
    One year into its tenure, how has the new New Zealand Government performed on issues of technology and telecommunications?
  • More blogs »

Tags

Back to top

Featured