Ads by TechWords

See your link here
Subscribe to our e-mail newsletters
For more info on a specific newsletter, click the title. Details will be displayed in a new window.
Security
Virus and Vulnerability Roundup
Computerworld Daily News (First Look and Wrap-Up)
Computerworld Blogs Newsletter
The Weekly Top 10
More E-Mail Newsletters 
 

Serious holes in antivirus software

May 11, 2005 12:00 PM ET

PC World - SAN FRANCISCO -- What if the bad guys found ways to infiltrate your computer through the very antivirus software that you thought was protecting you? Recent discoveries suggest that this scenario isn't so far-fetched.

If you have the latest antivirus definitions, aren't you protected? Not necessarily. Most programs have an automatic update feature that's turned on by default, but the tool may update only the definitions, not other software modules such as the scanning engine. The good news: Several antivirus software companies have patched their programs to fix this vulnerability.

McAfee, for example, updated the scanning engine of its VirusScan software to block a hole that could let a malicious hacker control your PC while the engine appears to be scanning for viruses. The vulnerability affects all versions of VirusScan and Internet Security Suite that run on all versions of Windows from 98 through XP.

McAfee says that most users should have received its fix via automatic updates. But to be sure, confirm that you have VirusScan engine 4.4.00 or later. For more on the patch, visit McAfee's virusscan 4320 buffer overrun vulnerability page.
At about the same time, Symantec fixed a similar hole in its Norton AntiVirus scanning engine. (For further information on the vulnerability, go to Symantec's security response page.) The scanner is included in such Symantec products as Norton AntiVirus 2004 for Windows, Norton Internet Security 2004 Professional for Windows, and Norton System Works 2004 for Windows (the 2003 and 2005 versions of these products aren't at risk because they lack the code that has the vulnerability). You can obtain the updated antivirus engine from a Symantec support page.

Finally, Trend Micro and F-Secure have fixed a similar hole in their antivirus scanning engine. If you use Trend Micro programs, such as PC-cillin Internet Security, you need scanning engine 7.510 (for details, visit the relevant Trend Micro page). If you use an F-Secure product, such as Anti-Virus 2004 or 2005, read F-Secure's security bulletin and pick up the most recent version.


Reprinted with permission from

For more PC news, visit PCWorld.com.
Story copyright 2009 PC World Communications. All rights reserved.

Additional Resources

POLL RESULTS
Accelerate your knowledge of the IT world you inhabit by viewing the results of a series of polls taken by your IT peers. These polls of 100+ IT professionals each are available for full viewing. They cover key topics such as virtualization, processor performance, green IT, cloud computing and many others. Be a part of the buzz.
WEBINAR
Attend this webinar and learn how to:
  • Free up development cycles that can be used to increase the functionality of the application
  • Eliminate the need to develop multiple BIRT web pages that differ only in visual style
  • Create a single BIRT design that shows the same data aggregated and calculated in different ways
  • Attend now!
WHITE PAPER
Utilizing demand intelligence improves the precision of pricing, product assortments, channel/store placement, and promotion, which are all essential for sustainable revenue management performance. Learn more, download this free whitepaper today.

White Papers & Webcasts

LIVE Jul 21, 2009 02:00 PM ET
 

Security and Trust: The Backbone of Doing Business Over the Internet
In this paper you will gain insights on how to encrypt sensitive information and help improve customer confidence....  

Horror stories: Managing IT Across Multiple Locations
How one extra sharp IT manager eliminates daily agony, hassle and repetition....

Phishing Alert: The Latest Tactics and Potential Business Impact
Read this white paper to learn how phishing attacks work, and how to avoid them....  

vSphere and Double-Take Software: Optimize while you Virtualize
Hear from VMware and Double-Take Software in this On Demand Webcast. Learn how to maximize your VMware vSphere deployments and optimize your workloads...

An All-in-One Approach to Web Security
Granting web access to employees poses challenges to IT administrators and introduces unique security risks. Even as companies have perfected their security techniques...  

How to Reduce Eclipse BIRT Development Effort for Data Visualizations
Web applications can come with a long list of visualization requirements for structured data. By delivering your output through the BIRT Interactive Viewer,...

The Hidden Dangers of Spam
Beyond the well-understood productivity drain that spam inflicts on businesses, threats posed by illicit email circulating through a network are causing many security...  

Accelerating Your Mobile Workers: Controlling the Uncontrollable
Today's workforce is truly mobile. Unlike the managed environment of the office LAN, remote users face many challenges to being productive while out...

Turning the Tide with Concentric Perimeter Email Protection
This paper will discuss the shortcomings of traditional spam protection solutions in dealing with the burgeoning spam problem and present a new solution...  

Disaster Recovery 2008: Reduced Costs and Improved Performance
How long can your Enterprise afford to be without your data? With an accelerated disaster recovery program, you never have to answer this...