Skip to content

Biting the hand that feeds IT

The Register ®

Security:


Related Whitepapers

[Print][Mobile][Alerts]

Red alert over Symantec firewall flaw

Four bugs rated as 'potentially devastating'

Published Thursday 13th May 2004 21:04 GMT

Four new vulnerabilities have been identified in Symantec's personal firewall products.

Symantec warned yesterday that hackers could exploit the flaws to render targeted systems inoperable or execute remote code with kernel-level privileges. The problems were discovered during product testing of Symantec's client firewall application by security firm eEye Digital Security.

Affected consumer products include Symantec Norton Internet Security and Professional, Norton Personal Firewall and Norton AntiSpam. Versions of Symantec's enterprise products Symantec Client Firewall and Symantec Client Security are also affected.

Symantec has released patches through its LiveUpdate service and technical support channels. Users can obtain the patches in running LiveUpdate in much the same way they would do to obtain new anti-virus definitions.

Security firm Secunia warns that some of vulnerabilities are easy to exploit and may lend themselves to the design of worms. Thomas Kristensen, Secunia's CTO, said: "Because the vulnerability can be exploited using UDP traffic, the worm may be as fast and violent as the Slammer worm exploiting Microsoft SQL servers last year."

One day after patches were published, similar vulnerabilities in ISS's firewall products were exploited by the Witty worm: it did a pretty good job of trashing infected systems. This is yet another good reason to apply Symantec's update sooner rather than later. ®

Related stories

Witty attacks your firewall and destroys your data
Witty extinction
Vendors wary of MS Windows Firewall

Track this type of story as a custom Atom/RSS feed or by email.
Previous Article Next Article
whitepaper title

The Perfect (Virtual) Marriage

Get consistent virtual machine storage savings of 50% (often as high as 90%) with virtually no performance impact with NetApp deduplication..
whitepaper title

Making Green IT a Reality

Customer Perspectives on the Impact of Storage Vendor Decisions on Power, Cooling, & Space in Enterprise Data Centers.
Whitepapers

Top 20 storiesAll The Week’s HeadlinesArchiveSearch