Wilders Security Forums  

Go Back   Wilders Security Forums > Security Products > other anti-virus software
User Name
Password
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

 
 
Thread Tools Search this Thread
  #1  
Old February 10th, 2005, 04:13 PM
stormbyte stormbyte is offline
AV Expert
 
Join Date: Jul 2004
Posts: 97
Default Symantec Multiple Products UPX Parsing Engine Buffer Overflow

SS X-Force has reported a vulnerability in multiple Symantec products, which can be exploited by malicious people to compromise a vulnerable system.

The vulnerability is caused due to a boundary error in the DEC2EXE parsing engine used by the antivirus scanning functionality when processing UPX compressed files. This can be exploited to cause a heap-based buffer overflow via a specially crafted UPX file.

http://secunia.com/advisories/14179/

Mariusz
stormbyte.com
  #2  
Old February 10th, 2005, 04:28 PM
ronjor's Avatar
ronjor ronjor is offline
Global Moderator
 
Join Date: Jul 2003
Location: Texas
Posts: 46,204
Default Re: Symantec Multiple Products UPX Parsing Engine Buffer Overflow

Sounds a lot like this one posted yesterday.

http://www.wilderssecurity.com/showthread.php?t=65646
  #3  
Old February 10th, 2005, 04:30 PM
Blackcat's Avatar
Blackcat Blackcat is offline
Massive Poster
 
Join Date: Nov 2002
Location: UK
Posts: 3,826
Default Re: Symantec Multiple Products UPX Parsing Engine Buffer Overflow

Quote:
Originally Posted by stormbyte
Another reason to switch to ArcaVir?
Mariusz
Or to any of many other worthy AV's Possibly.

But I am sure that Symantec will have a fix for this soon. In fact they already have by the post that Ronjor has shown above!!!!!!

Too early to jump ship yet, particularly when your new version has only just come out! ArcaVir has had no time to settle down yet

Mks-Vir/ArcaVir can stand on its own two legs without (constant) plugging of switching to this AV because of shortcomings/vulnerabilities in other AV programs.

No disrespect, Mariusz, you have a good product.

Last edited by Blackcat : February 10th, 2005 at 04:40 PM.
  #4  
Old February 10th, 2005, 04:35 PM
ronjor's Avatar
ronjor ronjor is offline
Global Moderator
 
Join Date: Jul 2003
Location: Texas
Posts: 46,204
Default Re: Symantec Multiple Products UPX Parsing Engine Buffer Overflow

Symantec Patches High-Risk Vulnerability


Quote:
In response, the Cupertino, Calif.-based company has discontinued use of the DEC2EXE engine, which is no longer required to parse compressed files. Symantec officials said the company had already deleted the vulnerable engine from the majority of its products and had planned to complete the removal from all affected product lines during upcoming maintenance updates.
  #5  
Old February 10th, 2005, 04:38 PM
Stefan Kurtzhals's Avatar
Stefan Kurtzhals Stefan Kurtzhals is offline
AV Expert
 
Join Date: Sep 2003
Posts: 625
Default Re: Symantec Multiple Products UPX Parsing Engine Buffer Overflow

The funny part is, Symantec added a heuristic detection to catch files that contain this exploit (beside updating their scan engine).
__________________
Chuck Norris does not use any antivirus software. He knows the hashes of all clean software on earth. Even those that are not compiled yet. It is not known if he got that list from dividing by zero or counting to infinity.
  #6  
Old February 10th, 2005, 05:41 PM
stormbyte stormbyte is offline
AV Expert
 
Join Date: Jul 2004
Posts: 97
Wink Re: Symantec Multiple Products UPX Parsing Engine Buffer Overflow

Quote:
Originally Posted by Blackcat
Or to any of many other worthy AV's Possibly.

But I am sure that Symantec will have a fix for this soon. In fact they already have by the post that Ronjor has shown above!!!!!!

Problem with Norton - there are milions of outdated copies out there. Many of them are just trial versions that expired. People using them will think that they are protected.

Quote:
Too early to jump ship yet, particularly when your new version has only just come out! ArcaVir has had no time to settle down yet

mks_vir has been around for more then 17 years. Program was designed for polish market only but still..

Quote:
Mks-Vir/ArcaVir can stand on its own two legs without (constant) plugging of switching to this AV because of shortcomings/vulnerabilities in other AV programs.

Sorry but as far as I remember this was my first post about vulnerabilities in other AV programs. Please correct me if I'm wrong.

Mariusz

www.stormbyte.com

Last edited by stormbyte : February 11th, 2005 at 04:25 PM.
 

Wilders Security Forums > Security Products > other anti-virus software « Previous Thread | Next Thread »

Thread Tools Search this Thread
Search this Thread:

Advanced Search

Posting Settings
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Forum Jump


All times are GMT -4. The time now is 05:12 AM.


Powered by vBulletin® Copyright ©2000 - 2013, Jelsoft Enterprises Ltd.
Copyright ©2002 - 2013, Wilders Security Forums