F-Secure hit with antivirus vulnerabilities
Physician, heal thyself?
IDG News Service - F-Secure Corp. has patched several vulnerabilities in its security products, the most critical of which could be used to run unauthorized software on a victim's computer.
The most critical of these bugs affects F-Secure's antivirus products. A flaw in the way the software unpacks files that have been compressed using the LHA archiving format, could allow an attacker to crash the system, or even run unauthorized software on the computer, F-Secure said in an advisory, published Wednesday.
This flaw is related to a similar flaw in the Gzip decompression utility that was discovered last September, F-Secure said.
Security vendor Secunia ApS rates the bug as highly critical. The flaw affects F-Secure's Anti-Virus, Internet Gatekeeper and Internet Security product suites.
A second less-critical vulnerability in some of the company's antivirus software was also patched Wednesday. This flaw could be used by an attacker with access to the local system to get into unauthorized parts of the system in what is called a privilege escalation attack.
Users of some versions of F-Secure Anti-Virus and Internet Security have been automatically delivered the software patches for these flaws, F-Secure said. A list of which products require hotfixes can be found within F-Secure's security bulletins.
Also on Wednesday, F-Secure fixed a flaw in its Policy Manager Server that could be used by attackers to launch a denial of service attack against the security management software. Secunia rates this bug as "less critical."
- Google I/O 2013's Coolest Products and Services
- 10 Star Trek Technologies That are Almost Here
- 19 Generations of Computer Programmers
- 25 Must-Have Technologies for SMBs
- A walking tour: 33 questions to ask about your company's security
- 15 social media scams
- The 7 elements of a successful security awareness program
- IT Certification Study Tips
- Register for this Computerworld Insider Study Tip guide and gain access to hundreds of premium content articles, cheat sheets, product reviews and more.
- Protection for Every Enterprise: How BlackBerry 10 Security Works Get an IT-level review of BlackBerry® 10 Security, addressing data leakage protection, certified encryption, containerization and much more.
- A Comprehensive Strategy to Leverage Mobile A successful mobile strategy begins with a common platform for integrating and managing mobile devices and the corporate assets that are stored on...
- IDC - SAP Enterprise Mobility: Bringing a Cohesive Approach to a Complex Market This IDC white paper discusses key mobility trends and examines how SAP's mobile enterprise solutions map to meet organization's mobile requirements.
- The App Happy Enterprise This Computerworld playbook explores key aspects of the enterprise mobile revolution and provides a set of step-by-step directions on how to productively manage...
- Live Webcast
Storage Validation at Go Daddy: Best Practices from the World's #1 Web Hosting Provider - Storage Validation at Go Daddy: Best Practices from the World's #1 Web Hosting Provider
- Live Webcast
MFT and FileXpress - An Overview - Business users and applications exchange files on a regular basis. File transfer is a core part of the flow of business activity.
- Live Webcast
Bridging HTTP and FTP with FileXpress Internet Server - What if you could take an FTP server on your internal network, and allow external users (partners or customers) to securely access it...
- Bridging HTTP and FTP with FileXpress Internet Server What if you could take an FTP server on your internal network, and allow external users (partners or customers) to securely access it...
- MFT and FileXpress - An Overview Business users and applications exchange files on a regular basis. File transfer is a core part of the flow of business activity. All Security White Papers | Webcasts