<?xml version="1.0" encoding="UTF-8"?>

<rss version="2.0" xmlns:blogChannel="http://backend.userland.com/blogChannelModule">

<channel>
<title>Possible issue with Symantec AntiVirus in Security</title>
<link>http://www.dslreports.com/forum/r12623642</link>
<description></description>
<language>en</language>
<pubDate>Thu, 26 Nov 2009 08:53:07 EDT</pubDate>
<lastBuildDate>Thu, 26 Nov 2009 08:53:07 EDT</lastBuildDate>

<item>
<title>Symantec Vulnerability - high risk per Symantec</title>
<link>http://www.dslreports.com/forum/remark,12643101</link>
<description><![CDATA[<A HREF="/useremail/u/668609"><b>EGeezer</b></A> : This Topic deserves a bump since it involves a very large chunk of Symantec products that may be used by . <br><br>Here's a partial quote from Symantec; <br><br><div class="bquote">SYM05-003<br>February 8, 2005<br>Symantec UPX Parsing Engine Heap Overflow<br><br>Revision History<br>2/9/2005 - Updated Vulnerability details and mitigations. Updated CVE Candidate Number<br><br>Risk Impact<br>High<br><br>Overview<br>Symantec resolved a potential remote access compromise vulnerability reported by ISS X-Force. The vulnerability was identified in an early version of a Symantec antivirus scanning module responsible for parsing UPX compressed files that is still in limited use in some Symantec security products.<br><br>The vulnerable component fails to do proper bounds checks when analyzing certain container files for virus content. An attacker sending a specifically crafted UPX file could potentially compromise the targeted system.<br><br>Vulnerable Products (vulnerable builds/Maintenance Releases (MR) where indicated)<br>Enterprise Products<br>Norton AntiVirus for Microsoft Exchange 2.1	prior to build 2.18.85<br>Symantec Mail Security for Microsoft Exchange 4.01	build 461<br>Symantec Mail Security for Microsoft Exchange 4.01	build 459<br>	<br>Symantec Mail Security for Microsoft Exchange 4.01	build 458<br>Symantec Mail Security for Microsoft Exchange 4.5	build 719<br>Symantec AntiVirus/Filtering for Domino NT 3.1 	prior to build 3.1.1<br>Symantec Mail Security for Domino 4.0 	prior to build 4.0.1<br>Symantec AntiVirus/Filtering for Domino Ports 3.0	<br>    (AIX) 	prior to build 3.0.6<br>    (OS400, Linux, Solaris) 	prior to build 3.0.7<br>Symantec AntiVirus Scan Engine 4.0.X 	all versions<br>Symantec AntiVirus Scan Engine 4.3.X 	prior to build 4.3.3<br>Symantec AntiVirus Scan Engine for ISA 4.0.X	all versions<br>Symantec AntiVirus Scan Engine for ISA 4.3.x	prior to build 4.3.3<br>Symantec AntiVirus Scan Engine for Netapp Filer 4.0.X 	All versions<br>Symantec AntiVirus Scan Engine for Netapp Filer 4.3.X 	prior to build 4.3.3<br>Symantec AntiVirus Scan Engine for Netapp NetCache 4.0.X	All versions<br>Symantec AntiVirus Scan Engine for Netapp NetCache 4.3.X	prior to build 4.3.3<br>Symantec AntiVirus Scan Engine for Bluecoat 4.0.X 	All versions<br>Symantec AntiVirus Scan Engine for Bluecoat 4.3.X 	prior to build 4.3.3<br>Symantec AntiVirus Scan Engine for Filers 4.3.X 	prior to build 4.3.3<br>Symantec AntiVirus Scan Engine for Caching 4.3.X 	prior to build 4.3.3<br>	<br>Symantec AntiVirus for SMTP 3.1.X 	prior to build 3.1.7<br>Symantec Mail Security for SMTP 4.0	prior to build 4.0.2<br>Symantec Web Security 3.0 .1.X 	prior to build 3.0.1.70<br>Symantec BrightMail AntiSpam 4.0 	All<br>Symantec BrightMail AntiSpam 5.5 	All<br>	<br>Symantec AntiVirus Corporate Edition 9.0 	9.0.0.338<br>Symantec AntiVirus Corporate Edition 8.1.1 	Build 8.1.1.314a<br>Symantec AntiVirus Corporate Edition 8.1.1 	Build 8.1.1.319<br>Symantec AntiVirus Corporate Edition 8.1.1 	Build 8.1.1.323<br>Symantec AntiVirus Corporate Edition 8.1.1 	Build 8.1.1.329<br>	<br>Symantec AntiVirus Corporate Edition 8.01 	Build 8.01.434<br>Symantec AntiVirus Corporate Edition 8.01 	Build 8.01.437<br>Symantec AntiVirus Corporate Edition 8.01 	Build 8.01.446<br>Symantec AntiVirus Corporate Edition 8.01 	Build 8.01.457<br>Symantec AntiVirus Corporate Edition 8.01 	Build 8.01.460<br>Symantec AntiVirus Corporate Edition 8.01 	Build 8.01.464<br>Symantec AntiVirus Corporate Edition 8.01 	Build 8.01.471<br>	<br>Symantec Client Security 2.0 	Build 9.0.0.338<br>Symantec Client Security 1.1.1 	MR1 Build 8.1.1.314a<br>Symantec Client Security 1.1.1 	MR2 Build 8.1.1.319<br>Symantec Client Security 1.1.1 	MR3 Build 8.1.1.323<br>Symantec Client Security 1.1.1 	MR4 Build 8.1.1.329<br>Symantec Client Security 1.1.1 	MR5 Build 8.1.1.336<br>	<br>Symantec Client Security 1.0.1 	MR3 Build 8.01.434<br>Symantec Client Security 1.0.1 	Build 8.01.437<br>Symantec Client Security 1.0.1 	MR4 Build 8.01.446<br>Symantec Client Security 1.0.1 	MR5 Build 8.01.457<br>Symantec Client Security 1.0.1 	MR6 Build 8.01.460<br>Symantec Client Security 1.0.1 	MR7 Build 8.01.464<br>Symantec Client Security 1.0.1 	MR8 Build 8.01.471<br>Symantec Gateway Security 2.0, 2.0.1 - 5400 Series	<br>Symantec Gateway Security 1.0 - 5300 Series	<br><br>Consumer Products<br><br>Symantec Norton Antivirus 2004 for Windows<br>Symantec Norton Internet Security 2004 (pro) for Windows<br>Symantec Norton System Works 2004 for Windows<br>Symantec Norton Antivirus 8.0 for Macintosh<br>Symantec Norton Internet Security 2.0 for Macintosh<br>Symantec Norton System Works 7.0 for Macintosh<br>Symantec Norton Antivirus 2004 for Macintosh<br>Symantec Norton Internet Security 2004 for Macintosh<br>Symantec Norton System Works 2004 for Macintosh<br>Symantec Norton Antivirus 9.0 for Macintosh<br>Symantec Norton Internet Security for Macintosh 3.0<br>Symantec Norton System Works for Macintosh 3.0<br><br>Non-Vulnerable Products (initial non-vulnerable build/Maintenance Release (MR) where indicated)<br>Enterprise Products<br>Norton AntiVirus for Microsoft Exchange 2.18 	2.18.82 and earlier<br>Norton AntiVirus for Microsoft Exchange 2.18 	2.18.85 and later<br>Symantec Mail Security for Microsoft Exchange 4.0 	Build 456 and earlier<br>Symantec Mail Security for Microsoft Exchange 4.0 	Build 463<br>Symantec Mail Security for Microsoft Exchange 4.0 	Build 465<br>Symantec Mail Security for Microsoft Exchange 4.5 	Build 736<br>Symantec Mail Security for Microsoft Exchange 4.5 	Build 741<br>Symantec Mail Security for Microsoft Exchange 4.5 	Build 743<br>	<br>Symantec Mail Security for Microsoft Exchange 4.6	<br>Symantec AntiSpam for SMTP 3.1	<br>Symantec AntiVirus/Filtering for Domino NT 3.1 	3.1.1<br>Symantec Mail Security for Domino 4.0 	4.0.1<br>Symantec Mail Security for Domino 4.1 	All<br>Symantec AntiVirus/Filtering for Domino Ports 3.0	<br>    (AIX) 	3.0.6<br>    (OS400, Linux, Solaris) 	3.0.7<br>Symantec AntiVirus Scan Engine 4.3 	4.3.3<br>Symantec AntiVirus Scan Engine for ISA 4.3.X 	4.3.3<br>Symantec AntiVirus Scan Engine for Netapp Filer 4.3.X 	4.3.3<br>Symantec AntiVirus Scan Engine for Netapp NetCache 4.3.X 	4.3.3<br>Symantec AntiVirus for Caching 	4.3.3<br>Symantec AntiVirus Scan Engine for Microsoft Portal Server 4.3.X	<br>Symantec AntiVirus Scan Engine for Bluecoat 4.3.X 	4.3.3<br>Symantec AntiVirus Scan Engine for Filers 4.3.X 	4.3.3<br>Symantec AntiVirus for Microsoft Office	<br>SharePoint Portal Server 2003 	All<br>Symantec AntiVirus for SMTP 3.1 	3.1.7<br>Symantec Mail Security for SMTP 4.0 	4.0.2<br>Symantec Mail Security for SMTP 4.1 	<br>Symantec Web Security 3.0 	3.0.1.70<br>Symantec BrightMail AntiSpam 6.0 All<br>Symantec BrightMail AntiSpam 4.0     (Disable DEC2EXE per mitigation instructions)<br>Symantec BrightMail AntiSpam 5.5     (Disable DEC2EXE per mitigation instructions)<br>	<br>Symantec AntiVirus Corporate Edition 9.0 	Build 9.0.1.1.1000<br>Symantec AntiVirus Corporate Edition 8.1.1 	Build 9.1.0.825a<br>Symantec AntiVirus Corporate Edition 8.1.1 	Build 8.1.1.366<br>Symantec AntiVirus Corporate Edition 8.0 	Build 8.01.9374<br>Symantec AntiVirus Corporate Edition 8.0 	Build 8.01.9378<br>Symantec AntiVirus Corporate Edition 8.0 	Build 8.01.425a/b<br>Symantec AntiVirus Corporate Edition 8.0 	Build 8.01.429c<br>Symantec AntiVirus Corporate Edition 8.0 	Build 8.01.501<br>	<br>Symantec Client Security 2.0.1 	MR1 Build 9.0.1.1.1000<br>Symantec Client Security 2.0.2 	MR2 Build 9.0.1.2.1000<br>Symantec Client Security 2.0.3 	MR3 Build 9.0.1.3.1000<br>	<br>Symantec Client Security 1.1 	Initial STM Release Build 8.1.0.825a<br>Symantec Client Security 1.1.1 	MR6 Build 8.1.1.366<br>Symantec Client Security 1.0 	Build 8.01.9374<br>Symantec Client Security 1.0.0 	Build 8.01.9378<br>Symantec Client Security 1.0.1 	MR1 Build 8.01.425a/b<br>Symantec Client Security 1.0.1 	MR2 Build 8.01.429c<br>Symantec Client Security 1.0.1 	MR9 Build 8.01.501<br>	<br>Symantec Norton AntiVirus 7.6     (does not install the vulnerable module)<br>Symantec Mail-Gear	<br>Symantec I-Gear	<br>Symantec AntiVirus for HandHelds - Corporate Edition (does not install the DEC2EXE module)<br>Symantec Client Security for Nokia Communicator (does not install the DEC2EXE module)<br><br>Consumer Products<br>Symantec Norton Antivirus 2003<br>Symantec Norton Internet Security 2003 (pro)<br>Symantec Norton System Works 2003<br>Symantec Norton AntiVirus 2005<br>Symantec Norton Internet Security 2005<br>Symantec Norton System Works 2005 (Premier)<br>Symantec AntiVirus for Handhelds (does not install the DEC2EXE module)<br></DIV>This from CRN - &raquo;<A HREF="http://www.crn.com/sections/security/security.jhtml?articleId=59302444" >www.crn.com/sections/security/se&middot;&middot;&middot;59302444</A><br><br>Symantec alert at &raquo;<A HREF="http://securityresponse.symantec.com/avcenter/security/Content/2005.02.08.html" >securityresponse.symantec.com/av&middot;&middot;&middot;.08.html</A><br><br>&raquo;<A HREF="http://xforce.iss.net/xforce/alerts/id/187" >xforce.iss.net/xforce/alerts/id/187</A> ]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,12643101</guid>
<pubDate>Fri, 11 Feb 2005 12:29:47 EDT</pubDate>
</item>

<item>
<title>Re: Possible issue with Symantec AntiVirus</title>
<link>http://www.dslreports.com/forum/remark,12624113</link>
<description><![CDATA[<A HREF="/useremail/u/809982"><b>Brian in MD</b></A> : Maybe for the standalone products, but the way I (and the others here) am reading this, you will actually have to apply a product update to secure your PC - at least for the Enterprise level application.]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,12624113</guid>
<pubDate>Wed, 09 Feb 2005 13:07:53 EDT</pubDate>
</item>

<item>
<title>Re: Possible issue with Symantec AntiVirus</title>
<link>http://www.dslreports.com/forum/remark,12623708</link>
<description><![CDATA[<A HREF="/useremail/u/229804"><b>B</b></A> : Interesting exploit.<br><br>Symantec's page implies that an ordinary LiveUpdate will cure the problem for those affected.<br><br>-- B<br><SMALL>--<br>In a realm outside causality and function</SMALL>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,12623708</guid>
<pubDate>Wed, 09 Feb 2005 12:09:24 EDT</pubDate>
</item>

<item>
<title>Possible issue with Symantec AntiVirus</title>
<link>http://www.dslreports.com/forum/remark,12623642</link>
<description><![CDATA[<A HREF="/useremail/u/809982"><b>Brian in MD</b></A> : Saw this today - &raquo;<A HREF="http://xforce.iss.net/xforce/alerts/id/187" >xforce.iss.net/xforce/alerts/id/187</A><br><br>which references: &raquo;<A HREF="http://www.symantec.com/avcenter/security/Content/2005.02.08.html" >www.symantec.com/avcenter/securi&middot;&middot;&middot;.08.html</A><br><br>Anybody have any other information on this?  So far Symantec hasn't been able to give me too much, and the updates their techsupport page refers to don't seem to exist.]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,12623642</guid>
<pubDate>Wed, 09 Feb 2005 12:01:12 EDT</pubDate>
</item>

</channel>
</rss>
