All the latest UK technology news, reviews and analysis

McAfee flaw leaves users wide open

by Iain Thomson

More from this author

18 Mar 2005

Comment: 1

  • Tweet this

Security research firm ISS has issued an advisory warning of a "serious flaw" in McAfee's antivirus library system that leaves users wide open to attack.

The flaw is in 23 versions of McAfee's products, and stems from a vulnerability in the antivirus library which the software uses to check for malware. ISS warned that ISPs, businesses and home users are all at risk.

"ISS has shipped protection for a flaw discovered by X-Force in McAfee AntiVirus Library versions prior to 4400," said the advisory.

"The Library is widely relied on to provide antivirus capabilities to desktop, server and gateway systems. Also, several large vendors and ISPs implement the Library in their products."

The flaw can be exploited if a hacker sends an email to the target with a specially crafted 'Lha' file, a type of format read by many software engines.

The user does not need to open anything; instead the file overwhelms the library's buffer and allows code to be executed on the target machine.

MacAfee was unavailable for comment. The ISS advisory can be seen here.

Do you agree?

 

Add your comment

We won't publish your address
By submitting a comment you agree to abide by our Terms & Conditions. Your comment will be moderated before publication.

Poll

IT priorities for 2012

What is the most important IT priority for your company this year?

99%

0%

1%

0%

0%

Connect with V3.co.uk

Sign up to our daily or weekly newsletters

Accurev

Top 5 software development challenges

This paper focuses on a series of best practices and techniques for development teams looking to improve their software development processes

Talend

Rubbish in, rubbish enterprise

Why good data management at all levels is essential in the modern business (video, 6mins)

VB.Net (2008) Developer with MVP experience

Our client who are a large Pharmaceutical Company are...

IT Support (CCNA/CCIE)

IT Support Engineer (CCNA/CCIE) My client is a leading...

Problem Analyst

Company Information Atos is an international information...

Presales Consultant

Job Title Presales Consultant / Presales Executive...

To send to more than one email address, simply separate each address with a comma.