No. 1 Story

ACCC clears Optus to scrap HFC network and use NBN instead

The ACCC has cleared, provisionally, the proposed deal between Optus and NBN Co under which Optus is to be paid around $800m to shut down its HFC network and transfer customers onto the NBN. read more

Related Articles

Symantec, sees, eyetoeye, with, eEye, critical, antivirus, flaw
Whenever an AVG customer searches the web, sites carrying the VeriSign Trust Seal will...
Emerging Australian security powerhouse TrustDefender is quietly beavering away and winning big deals in...
Today's release of the report "In the Crossfire: Critical Infrastructure in the Age of...
Early WiMAX networks will have a number of security vulnerabilities, according to ABI Research,...
Symantec Corp. has announced security products for Vista including beta versions of the Norton...

Symantec sees eye-to-eye with eEye on critical antivirus flaw

Business IT - Security

Symantec has acknowledged the vulnerability in its Symantec Client Security and Symantec AntiVirus Corporate Edition (note: Norton Antivirus is not affected as previously reported) as a high impact risk and has issued a range of intrusion detection signatures (IDS) and intrusion prevention signatures as an interim fix for users.

Researchers at intrusion prevention software company eEye Digital Security brought the vulnerability to the attention of Symantec and the world yesterday. Symantec has since confirmed the vulnerability as genuine and affecting its Symantec Client Security 3.1 and Antivirus Corporate Edition 10.1 products.

"Symantec was notified that Symantec Client Security and Symantec AntiVirus Corporate Edition are susceptible to a potential stack overflow. Exploiting this overflow successfully could potentially cause a system crash, or allow a remote or local attacker to execute arbitrary code with System level rights on the affected system," a Symantec statement says.

"Symantec would like to thank eEye Digital Security for reporting this issue, and working with us on the resolution."

Symantec has released a range of IDS to signatures, available to customers via its LiveUpdate service, to detect attempts to exploit the flaw. It has also released a range of IPS signatures via LiveUpdate saying:

"As a mitigation strategy, Symantec Security Response has also made available IPS signatures for Symantec Client Security to protect against exploits of the described vulnerability. Symantec recommends customers immediately apply the latest Security Update to protect against potential related attacks."