Feeds

CA in malformed archives malware risk

Anti-virus protection turned against users

Top 5 reasons to deploy VMware with Tegile

CA has updated its anti-virus software to guard against a brace of flaws that created a means for hackers to turn the security protection software against its users.

Both bugs involved problems in processing malformed CAB archives. Successful exploitation of the vulnerabilities potentially allows execution of arbitrary code (malware) or system crashes thanks to that perennial hacker favourite, buffer overflow flaws.

The vulnerabilities affect CA Anti-Virus and eTrust security packages, enterprise versions of these products, as well as systems management and backup suites that bundle the security software. CA has published an update (30.6, if you must know) designed to address the flaws, which were reported by security researchers via 3Com Tipping Point's Zero Day Initiative (advisories here and here).

CA's advisory can be found here.

Processing archived files is something of an Achilles heel for anti-virus products in general. The issue came to the fore around two years ago after security tools vendor ISS issued alerts over similar but distinct vulnerabilities in various security packages from Symantec, involving the processing of UPX compressed files; and anti-virus products from F-Secure and Trend Micro, both involving the handling of ARJ archive files.

More recently, Trend Micro had a problem with UPX compressed files back. Anti-virus products are designed to keep users safe from virus attacks. Flaws, such as the bugs in CA's software, illustrate these security packages can become the source of security bugs. The problem is nowhere near severe enough to spark much of a rethink by vendors, much less changes in anti-virus user buying behaviour, but it does illustrate the problems of adding additional layers of protection rather than making systems secure in the first place. ®

Beginner's guide to SSL certificates

More from The Register

next story
Regin: The super-spyware the security industry has been silent about
NSA fingered as likely source of complex malware family
Why did it take antivirus giants YEARS to drill into super-scary Regin? Symantec responds...
FYI this isn't just going to target Windows, Linux and OS X fans
Privacy bods offer GOV SPY VICTIMS a FREE SPYWARE SNIFFER
Looks for gov malware that evades most antivirus
Home Office: Fancy flogging us some SECRET SPY GEAR?
If you do, tell NOBODY what it's for or how it works
HACKERS can DELETE SURVEILLANCE DVRS remotely – report
Hikvision devices wide open to hacking, claim securobods
'Regin': The 'New Stuxnet' spook-grade SOFTWARE WEAPON described
'A degree of technical competence rarely seen'
Syrian Electronic Army in news site 'hack' POP-UP MAYHEM
Gigya redirect exploit blamed for pop-rageous ploy
Astro-boffins start opening universe simulation data
Got a supercomputer? Want to simulate a universe? Here you go
prev story

Whitepapers

Free virtual appliance for wire data analytics
The ExtraHop Discovery Edition is a free virtual appliance will help you to discover the performance of your applications across the network, web, VDI, database, and storage tiers.
Getting started with customer-focused identity management
Learn why identity is a fundamental requirement to digital growth, and how without it there is no way to identify and engage customers in a meaningful way.
The total economic impact of Druva inSync
Examining the ROI enterprises may realize by implementing inSync, as they look to improve backup and recovery of endpoint data in a cost-effective manner.
High Performance for All
While HPC is not new, it has traditionally been seen as a specialist area – is it now geared up to meet more mainstream requirements?
Website security in corporate America
Find out how you rank among other IT managers testing your website's vulnerabilities.