Thursday, December 22, 2005

Symantec Vulnerability

Symantec on Wednesday named more than 60 of its products as affected by the critical vulnerability disclosed earlier this week, and said it was pushing out a "heuristic detection that would spot potential exploits. However, no patches have yet been released.

The number of impacted products was among the largest ever for a single vulnerability, and demonstrated the risk of reusing code in a large group of programs.

The bug, which was made public Tuesday by researcher Alex Wheeler, is in how Symantec's AntiVirus Library, part of virtually all the Cupertino, Calif.-based security giant's programs, handles RAR compressed files. RAR files are created by the WinRAR compression utility, developed and sold by RarLab. (more) Information Week