Infesting you with Virus News
 

News

Contributed by: EglÄ—
Date: August 26, 2009
EglÄ—
9
Vote
0

Symantec Products Are Experiencing Security Problems

 

symanteconline.gifThe chain of Symantec software programs is very long and includes the well-known Symantec Antivirus, Symantec Backup Exec, Symantec Log Viewer and many others. Out of this variety of Symantec software products, several specific products were selected by wicked users to perform malign actions related to sensitive and often unprotected computer systems.

First, let me ask you a question: Are you using Symantec programs such as Symantec Mail Security, Symantec BrightMail Appliance and Symantec Data Loss Prevention Enforce/Detection Servers? If your answer is yes, you should direct your attention to this really important security news pertaining to these particular Symantec programs. The point is that a serious vulnerability exists in the programs mentioned above. Speaking of Symantec, if you can remember, a vulnerability was found in the Symantec Reporting Server more than two months ago as well.

In the table below, you will find Symantec products and versions that were confirmed to be affected:

Symantec Mail Security for Domino versions 7.5.6, 7.5.5.32, 7.5.4.29, 7.5.3.25, and 8.0
Symantec Mail Security for Microsoft Exchange versions 5.0.12, 5.0.11, 5.0.10, 6.0.8, 6.0.7, and 6.0.6 
Symantec Mail Security for SMTP versions 5.0.x 
Symantec Mail Security Appliance/ Symantec BrightMail Appliance versions 5.0.x and later 
Symantec BrightMail Appliance versions 8.0.0 and 8.0.1 
Symantec Data Loss Prevention Enforce/Detection Servers version 7.2 
Symantec Data Loss Prevention Enforce/Detection Servers for Windows versions 8.1.1 and 9.0.1 
Symantec Data Loss Prevention Enforce/Detection Servers for Linux versions 8.1.1 and 9.0.1 
Symantec Data Loss Prevention Endpoint Agents versions 8.1.1 and 9.0.1 

 Table 1.  Affected products and versions

It is important for users to note that in certain vulnerable Symantec products, the Autonomy KeyView module processes have been set apart from the Symantec application processes and are performed with limited rights. Now, are you interested in what attackers obtain by exploiting this vulnerability? Attackers could exploit this weakness in order to compromise an accessible system and fulfill the execution of arbitrary code. Symantec software programs are compatible with Windows version such as 2000/XP/Vista. Some of the files related to, for example, Windows 2000 include: n3bridge.sys, 3cisati.sys, dfs.sys, winacpci.sys and nwgina.dll

Are you prepared to find out more about this vulnerability? What exactly is the cause of this weakness? This vulnerability is produced by an integer overflow error in the Autonomy KeyView Viewer for Excel (xlssr.dll) while dealing with XLS documents. They contain a false Shared String Table (SST) record, which could be exploited by malicious users with an evil purpose to crash an insecure application or execute arbitrary code. This can be accomplished if a user is convinced to view an infectious Excel file.

Lastly, I will tell you some good news. Despite the fact that you might be a current user of one affected Symantec program, you must be curious about a solution to this big security problem, including current users of all other vulnerable Symantec applications. Users are strongly recommended to look through the vendor advisory for a patch matrix. Luckily, updates are already available. So, you can fix this vulnerability by applying the appropriate updates to whichever affected product and use the particular program in a safer environment.

User Comments

Name:
Email:
Website:
Comment:
Please type 5-digit security code below:
Captcha image for spam protection

Software Downloads

Free Spyhunter Scanner (Spyware/Trojan Detection). DETECT Spyware, Trojans, Worms, Viruses and malware on your PC absolutely FREE.
Award Winning software, Fixes registry and improves computer performance. Created by a division of Symantec, this tool will scan your registry and find errors that can be later cleaned either individually or all together.
The tool is used to prevent the installation of spyware and other potentially unwanted software. As soon as you download it, you will be able to protect your system.

Latest Comments

September 3, 2010
how can i remove sdfsdf, i cannot get into windows? more..
September 3, 2010
hi here is parteek kaushal i just want to tell that smone has copied my pics with my frnd n she is abusing... more..
September 3, 2010
Hello I am new here. Im sorry if this is not the right place for this post. My name... more..
more comments..
rss
Home > Computer Security > Symantec Products Are Experiencing Security Problems