Slashdot Mirror


Symantec Antivirus May Execute Virus Code

An anonymous reader writes "Symantec has admitted that a serious vulnerability exists in the way its scanning engine handles Ultimate Packer for Executables. According to a ZDNet article, this means the scanner would execute the malicious program instead of catching it. Tim Hartman, senior technical director for Symantec Asia Pacific, said: "A vulnerability is not a vulnerability till somebody discovers it but because this is now known, somebody could craft an e-mail, mass mailer or a virus that takes advantage of it. It affects our firewalls, antispam, all the retail products and the enterprise products as well"" Symantec recommends you immediately patch your software.

29 of 388 comments (clear)

  1. Obligatory... by ral315 · · Score: 2, Funny

    May I be the first to congratulate our executable overlords!

    1. Re:Obligatory... by Ford+Prefect · · Score: 1, Funny

      Actually, these sorts of bugs are why I don't use antivirus software... ;-)

      --
      Tedious Bloggy Stuff - hooray?
  2. Immediate patch... by same_old_story · · Score: 2, Funny

    http://fedora.redhat.com/

    1. Re:Immediate patch... by lucabrasi999 · · Score: 2, Funny

      Thanks. Now, can you explain how my company is to quikly move all of thousands of employees and all of our internal Windows-based applications to redhat in the next 24 hours?

    2. Re:Immediate patch... by russint · · Score: 3, Funny

      Thanks. Now, can you explain how my company is to quikly move all of thousands of employees and all of our internal Windows-based applications to redhat in the next 24 hours?

      Amphetamine.

      --
      ^^
  3. Damn! by JanneM · · Score: 3, Funny

    No time to waste! Systems may already be infected, so better get offline immediately, review what installed software is at risk and start figuring out a way to get the patches... no, wait, I run linux.

    Wonder what's on TV tonight?

    --
    Trust the Computer. The Computer is your friend.
    1. Re:Damn! by spiffyinferno · · Score: 2, Funny

      "Wonder what's on TV tonight?" I believe you can catch the systemic failures of windows pc's everywhere in primetime- with a Bill Gates wardrobe malfunction at the break.

      --
      What would jesus do.. with open source software?
    2. Re: Damn! by Black+Parrot · · Score: 3, Funny


      > no, wait, I run linux. Wonder what's on TV tonight?

      Switch to Gentoo and you'll have something to do tonight.


      --
      Sheesh, evil *and* a jerk. -- Jade
    3. Re: Damn! by drinkypoo · · Score: 2, Funny

      Switch to Gentoo and you'll have something to do tonight.

      And tomorrow night, and the night after that...

      --
      "You're right," Fisheye says. "I should have set it on 'whip' or 'chop.'"
  4. Imagine how pissed you would be by Anonymous Coward · · Score: 2, Funny

    if you went in for an STD test and they gave you herpes!

    1. Re:Imagine how pissed you would be by finse · · Score: 2, Funny

      I thought it was odd when the med tech asked me if I wanted a 'happy ending'..

      --
      Paranoid tinfoil hat crowd say Y here, everyone else say N.
  5. Re:Immediately patch? Really? by mrighi · · Score: 5, Funny

    That's because they gave out the wrong link. What they really meant to say was, "Symantec recommends you immediately patch your software."

  6. Re:huh? by pegasustonans · · Score: 4, Funny

    No, you've got it all wrong. The person didn't actually exist, and all of the people who thought about the person existing didn't exist either. And all of the people who thought the person might or might not exist, but probably didn't, and should therefore be disregarded, were very clever and were hired by anti-virus companies to do their PR for them.

    --
    And all our yesterdays have lighted fools The way to dusty death. --Will
  7. Okay, Farkers... by Mmm+coffee · · Score: 5, Funny

    You know all those idiotic flamewars that spring up whenever the "irony" tag is used?

    Once and for all - THIS is irony. You can shut up now.

    1. Re:Okay, Farkers... by c4miles · · Score: 3, Funny

      What, addressing an entire community of /.ers as Farkers whilst making a point about irony?

      Yes. This is irony.

  8. Re:huh? by LourensV · · Score: 3, Funny

    I think he is a quantum physicist...

  9. Re:Better than just free by lucabrasi999 · · Score: 4, Funny
    "Use of AVG Free Edition within any organization or for commercial purposes is strictly prohibited."

    I guess Santa isn't Dancing anymore.

  10. Yeah, right. by Black+Parrot · · Score: 1, Funny


    > > "A vulnerability is not a vulnerability till somebody discovers it..."

    > Huh?

    Sir Lancelot: "I hate to go into battle with this big f*ing hole in my chainmail, but fortunately my tabard will hide it."

    --
    Sheesh, evil *and* a jerk. -- Jade
  11. Here's the scanner source code: by Anonymous Coward · · Score: 2, Funny

    #!/bin/sh
    echo Scanning...
    for file in `find /`
    do
    sudo $file
    if system_still_running
    then
    echo File $f OK
    fi
    done

  12. Did I miss something? by Anonymous Coward · · Score: 2, Funny

    Did Microsoft buy out Norton last week?

  13. Re:huh? by worst_name_ever · · Score: 4, Funny

    You must not have gotten the latest memo from Symantec: "We apologise again for the fault in the antivirus software. Those responsible for sacking the people who have just been sacked, have been sacked."

    --

    In Soviet Rush, today's Tom Sawyer gets high on you.
  14. Re:huh? by MedBob · · Score: 1, Funny

    I've always suspected that they had a cat in a box somewhere....

  15. Re:Yet another reason by kyojin+the+clown · · Score: 3, Funny
    Symantec has excellent corporate support and management features

    True.

    If only it had excellent anti-virus features to go with them.

  16. Re:Immediately patch? Really? by wo1verin3 · · Score: 2, Funny

    >> Okay, so I'm being lazy and don't want to call them

    Translation: I didn't pay for the software so I can't call them

  17. Quote of the day by ThoreauHD · · Score: 2, Funny

    Tim Hartman, senior technical director for Symantec Asia Pacific, said:

    "A vulnerability is not a vulnerability till somebody discovers it...

    Impressive foresight. Another great security through obscurity business model.

    No tiny Tim, if your tire can be flattened, it will be. It's that simple.

  18. Re:Better than just free by Rick+Zeman · · Score: 5, Funny

    As long as it's not company policy ie. each employee that uses it is installing it for personal use, it's free.

    I worked for a company that refused to pay for AV, and we all had it on our desktops, except the managers.


    So what part of "home" did you all deliberately misunderstand?

  19. Re:Immediately patch? Really? by DarKnyht · · Score: 2, Funny

    You can always wait and switch to the Microsoft Anti-Virus that will ensure the safety of your computer by making sure it cannot run at all.

    --
    Voting them all out of office, now that's change I can believe in.
  20. Bad joke by slapout · · Score: 2, Funny

    Symantec Antivirus May Execute Virus Code

    I don't care if Symantec runs virus code, just as long as windows doesn't.

    --
    Coder's Stone: The programming language quick ref for iPad
  21. Re:Immediately patch? Really? by Donoho · · Score: 2, Funny

    You can always wait and switch to the Microsoft Anti-Virus

    I thought this was funny :">