Go Back   Armenian Knowledge Base > Technical sections > Software > Software Security

Reply
 
Thread Tools

Flaw found in Kaspersky antivirus
Old 05.10.2005, 09:31   #1
Moderator
 
acid's Avatar
 
Join Date: 09 2001
Location: South Korea, Gumi
Posts: 7,699
Blog Entries: 16
Rep Power: 7
Default Flaw found in Kaspersky antivirus

A "critical" flaw in Kaspersky Lab's antivirus software could let an attacker commandeer systems that use the products, a security researcher warned Monday.
The problem lies in Kaspersky's antivirus library, security researcher Alex Wheeler wrote in an advisory (download PDF of advisory here). The vulnerability likely affects multiple Kaspersky products on various platforms because the library is used throughout the company's consumer and corporate software, he said.
Additionally, third-party products that use Kaspersky's antivirus technology could also be vulnerable, Wheeler said.

A remote attacker could exploit the heap overflow flaw by sending a malformed CAB file--a compression file--to a vulnerable system, the French Security Incident Response Team said in an advisory. The CAB file could be sent in an e-mail, for example, and once the Kaspersky antivirus scanner had accepted it, the malicious code would be in the system. No user interaction is required, Wheeler said. FrSirt describes the issue as "critical," its highest rating.
A representative for Kaspersky in Moscow could not immediately comment on the issue and said that the Russian company would need to investigate.
Antivirus software is like low-hanging fruit to hackers, Yankee Group analysts wrote in a research paper released earlier this year. As the pool of easily exploitable security bugs in Microsoft Windows dries up, attackers are looking to security software for holes to get into systems, the analysts said.
At the Black Hat Briefings security conference this summer, researchers at Internet Security Systems outlined vulnerabilities in antivirus products. ISS has discovered bugs in products from security software makers including Symantec, McAfee, Trend Micro and F-Secure.

http://news.com.com/Flaw+found+in+Kaspersky+antivirus/2100-1002_3-5887857.html

Old 06.10.2005, 15:19   #2
Provocative
 
Red Stone's Avatar
 
Join Date: 09 2002
Location: Ilha dos Amores
Posts: 1,491
Rep Power: 5
Default

Oh! sh*t! Where can we feel safe???

Old 06.10.2005, 16:56   #3
инсценирующи
 
[ Xelgen ]'s Avatar
 
Join Date: 07 2002
Location: Fireplace of Ecotopia
Age: 38
Posts: 4,327
Rep Power: 5
Default

Hm, yes pretty..
BTW, dont' intsall KAV 2006 Beta, no your computers yet.. I've tested it, it is too buggy and it spoiled up my WinXP..

Old 06.10.2005, 17:19   #4
Авик
 
CyberJoe's Avatar
 
Join Date: 07 2002
Location: Yerevan
Age: 37
Posts: 1,348
Rep Power: 0
Default

A касперский вчера скачал апдейт и попросил впервые рестарта.. ет ер??
Reply




Реклама:
реклама

All times are GMT. The time now is 18:10.
Top

Powered by vBulletin® Copyright ©2000 - 2024, Jelsoft Enterprises Ltd.