Technology news and Jobs arrow Information Technology News arrow McAfee apologizes for tardy alert about flaw fix
McAfee apologizes for tardy alert about flaw fix E-mail
by Stan Beer   
Tuesday, 18 July 2006
Security firm McAfee did not have its finest hour last week. First it discovered that it had a flaw in a major corporate security software product. Then it discovered that it had accidentally fixed the flaw. Then it took six months to alert users to the fact.

The flaw was found in McAfee ePolicy Orchestrator which is used to manage security software on millions of PCs at the firm's corporate and government client sites, including the US Department of Defence. The vulnerability could have allowed hackers to gain control of target computers, steal data, implant malware and delete files.

Fortunately for McAfee, one of its engineers fixed the flaw accidentally while making enhancements to the software in an upgrade.

However, instead of advising all of its customers to immediately upgrade to the new software in January because of the crictial design flaw, McAfee merely advised clients that its software update had feature enhancements.

Security firm eEye Digital, which is making a name for itself discovery flaws in other security firm's software, brought the flaw to the attention of McAfee and the public last week. In May, eEye discovered a serious flaw in Symantec's security software, which was subsequently fixed.

After the flaw became public knowledge, McAfee issued a public apology to its clients and advised them to upgrade the software. {moscomment}
Powered By Joomla Tags

Please enable JavaScript in your browser to post your comment!

 
< Next story in category   Previous story in the category >
iTWire user statistics Visitors last 30 days
694,279
Subscribers 15,210
#1 independent technology news advertise here
  •   *  
  • Search
  • AdvSeach
  • Login
  • Events
  • FreeStuff

- Advertisement -

Featured Whitepapers

Follow iTWire on Twitter

About iTWire

iTWire is all about technology news, information, jobs and community for the IT and telecommunications industry professional. Subscribe to our free ICT daily newsletter