Feeds

Single IPv6 packet KILLS Kaspersky-protected PCs, fix emerges

Windows PCs frozen to death by firewall bug

Internet Security Threat Report 2014

Kaspersky Lab has fixed a bug that could freeze PCs with Kaspersky Internet Security 2013 installed if they received a specially malformed IPv6 packet.

Earlier this week infosec bod Marc Heuse reported that sending a fragmented IPv6 network packet with multiple extension headers, one of which is unusually long, to a Windows computer with Kaspersky Internet Security 2013 installed will freeze up the machine completely. The Russian security biz confirmed the flaw, which it has fixed in its software, and apologised for the coding error.

In a statement, Kaspersky Lab stressed that the bug only crashed PCs, rather than creating a means to take control of them:

After receiving feedback from the researcher, Kaspersky Lab quickly fixed the error. A private patch is currently available on demand and an autopatch will soon be released to fix the problem automatically on every computer protected by Kaspersky Internet Security 2013.

Although Kaspersky Lab acknowledges the issue, it would like to stress that there was no threat of malicious activity affecting the PCs of any users who may have experienced this rare problem.

Kaspersky Lab would like to apologise for any inconvenience caused. Actions have been taken to prevent such incidents from occurring in the future.

In his advisory, Heuse revealed that the freeze flaw is not restricted to KIS 2013 but also affects any other Kaspersky products that bundle the same buggy firewall functionality.

Heuse said he only went public on Monday after failing to get a response from Kaspersky on the issue, which he first reported to the security firm in late January. ®

Choosing a cloud hosting partner with confidence

More from The Register

next story
Regin: The super-spyware the security industry has been silent about
NSA fingered as likely source of complex malware family
Privacy bods offer GOV SPY VICTIMS a FREE SPYWARE SNIFFER
Looks for gov malware that evades most antivirus
Patch NOW! Microsoft slings emergency bug fix at Windows admins
Vulnerability promotes lusers to domain overlords ... oops
HACKERS can DELETE SURVEILLANCE DVRS remotely – report
Hikvision devices wide open to hacking, claim securobods
'Regin': The 'New Stuxnet' spook-grade SOFTWARE WEAPON described
'A degree of technical competence rarely seen'
Astro-boffins start opening universe simulation data
Got a supercomputer? Want to simulate a universe? Here you go
prev story

Whitepapers

Why cloud backup?
Combining the latest advancements in disk-based backup with secure, integrated, cloud technologies offer organizations fast and assured recovery of their critical enterprise data.
Forging a new future with identity relationship management
Learn about ForgeRock's next generation IRM platform and how it is designed to empower CEOS's and enterprises to engage with consumers.
Designing and building an open ITOA architecture
Learn about a new IT data taxonomy defined by the four data sources of IT visibility: wire, machine, agent, and synthetic data sets.
How to determine if cloud backup is right for your servers
Two key factors, technical feasibility and TCO economics, that backup and IT operations managers should consider when assessing cloud backup.
Reg Reader Research: SaaS based Email and Office Productivity Tools
Read this Reg reader report which provides advice and guidance for SMBs towards the use of SaaS based email and Office productivity tools.