11 Oct 2007
A flaw in Kaspersky's Online Scanner could be exploited by malicious hackers to compromise a user's system.
However, when vnunet.com first approached the security firm about the flaw a spokesman said that he was "unaware of the problem" and that the company would issue a statement later.
A return call several hours later from Kaspersky's senior technology consultant, David Emm, produced a similar response.
"At the end of the day nothing is 100 per cent secure and anything humans can write, humans can undermine," he said, before going on to discuss two separate vulnerabilities.
When vnunet.com pointed out that we were talking about a flaw in the company's online scanner found today, he stated that he has not seen the problem. "I'm on a client day at Alton Towers," he said.
After further consultation, Emm called back again to say that users were covered by the version currently on the Kaspersky website.
"The software that's up there is the latest version and is the fixed version, " he said.
However, when asked whether this version will work if a user has the old version downloaded on their computer, Emm admitted that it would not.
"You will need to uninstall the one you had installed originally and install the latest version," he said.
When pressed as to whether Kaspersky will warn users about the situation, Emm said that it was "likely" but that he "cannot confirm it".
The vulnerability is caused by a format string error in the kavwebscan.CKAVWebScan ActiveX control which users have to download before using the scanner.
This could be exploited to execute arbitrary code, for example when a user visits a malicious website.
Security firm Secunia rated the vulnerability in an advisory as 'highly critical'.
The problem affects versions 5.0.93.1 and previous versions, but can be fixed by updating to version 5.0.98.0.
The problem was discovered by Stephen Fewer of Harmony Security and reported via iDefense Labs.
Latest stories from Security
Related articles
Related jobs
Poll
What is the most important IT priority for your company this year?
Sneak peek at the forthcoming glass-based machine
Connect with V3.co.uk
This paper focuses on a series of best practices and techniques for development teams looking to improve their software development processes
Why good data management at all levels is essential in the modern business (video, 6mins)
Job Specification For: Software Developer...
A global Investment Bank requires a Project Manager to...
Web Developer, .Net Software Developer - ASP.Net, C...
Verint Voice Recording Support Engineer (Verint / Nice...
Keep up to date with the latest products, services and technologies from the world's leading IT companies. IThound.com brings you over 2,000 white papers, case studies and analyst reports.
Do you agree?