On mySimon: Nike SB Eugene Backpack
BNET Business Network:
BNET
TechRepublic
ZDNet

August 22nd, 2007

Trend Micro, Zone Labs, ClamAV join list of insecure security products

Posted by Ryan Naraine @ 10:02 am

Categories: Botnets, Browsers, Data theft, Exploit code, Hackers, McAfee, Metasploit, Microsoft, Open source, Passwords, Patch Watch, Pen testing, Responsible disclosure, Rootkits, Spam and Phishing, Spyware and Adware, Symantec, Viruses and Worms, Vulnerability research, Zero-day attacks

Tags: Denial Of Service, Security, Check Point Software Technologies Ltd., Zone Labs Inc., Ryan Naraine

Trend Micro flaw opens door to hacker attacksAdd Trend Micro, Check Point Zone Labs and ClamAV to the long list of security products that put end users at risk of malicious hacker attacks.

The three vendors have all acknowledged various security vulnerabilities in a range of desktop and server products that could lead to arbitrary code execution, privilege escalation or denial-of-service conditions.

Trend Micro, which specializes in virus protection software, has issued patches for ServerProtect and the PC-cillin suite.

[SEE: Can you really trust your security vendor? ]

The ServerProtect update, rated “moderately critical” by Secunia, covers boundary errors and integer overflow errors that could be exploited to launch harmful code on a vulnerable installation. Two separate alerts from iDefense (here and here) outline the details and potential risks.

iDefense has also discovered about a remotely exploitable buffer overflow in Trend Micro Inc.’s SSAPI Engine that could allow attackers to execute arbitrary code with system level privileges.

The latest black-eye for security vendors has also affected Check Point Zone Labs. From an iDefense alert:

Local exploitation of an insecure permission vulnerability in multiple Check Point Zone Labs products allows attackers to escalate privileges or disable protection.

The vulnerability specifically exists in the default file Access Control List (ACL) settings that are applied during installation. When an administrator installs any of the Zone Labs ZoneAlarm tools, the default ACL allows any user to modify the installed files. Some of the programs run as system services. This allows a user to simply replace an installed ZoneAlarm file with their own code that will later be executed with system-level privileges.

Exploitation allows local attackers to escalate privileges to the system level. It is also possible to use this vulnerability to simply disable protection by moving all of the executable files so that they cannot start on a reboot.

ClamAV, the open-source anti-virus toolkit recently acquired by Sourcefire, has also struggled with security problems that could lead to sudden denial-of-service crashes. Secunia rates the ClamAV issues as “moderately critical.”

Ryan NaraineRyan Naraine is a journalist and security evangelist at Kaspersky Lab. He manages Threatpost.com, a security news portal. Here is Ryan's full profile and disclosure of his industry affiliations.


Email Ryan Naraine

For daily updates on Ryan's activities, follow him on Twitter.

Subscribe to Zero Day via Email alerts or RSS.

  • Talkback
  • Most Recent of 53 Talkback(s)
I have used several companies, they do this.
I spend money on some of these companies and some where a free test, McAfee, Norton, Panda, Avast, AVG, Nod32, Avira, and others.

I had two Computers running, one was Norton the other Panda, th... (Read the rest)
Posted by: troubled241 Posted on: 08/29/07 You are currently: a Guest | | Terms of Use
Why only these three?  georgeou | 08/22/07
The subject seems to say it all  Larry the Security Guy | 08/23/07
agree...  skipdog172@... | 08/23/07
I'd like to hear what has been seen  kcredden2 | 08/22/07
there is  aussieblnd@... | 08/23/07
Running ClamAV four years strong with little problems  YinToYourYang-22527499 | 08/22/07
just because you weren't there didn't mean...  TG2 | 08/23/07
just because you weren't there didn't mean...  aussieblnd@... | 08/23/07
If a tree falls on Bruce Cockburn...  TripleII | 08/23/07
You hope  TripleII | 08/23/07
"Moderately Critical"  comp_indiana | 08/22/07
I think  statseeker@... | 08/23/07
AV Companies  psmallwood@... | 08/23/07
AV Companies  aussieblnd@... | 08/23/07
Avast all the way  nhardin | 08/23/07
No offense to the author but....  ofur_matt | 08/23/07
It is getting rediculas  GreatWhite | 08/23/07
How about "Ridiculous"...  rmazzeo | 08/24/07
Have to Agree re the Tabloid Comment  DaffyDuck | 08/23/07
There are 2 of them I have USED  jackie40d@... | 08/23/07
didn't Consumer Reports just rank...  mark@... | 08/23/07
if is wasnt for the hackers (all three hats)  pcguy777 | 08/23/07
If you want a real security layer  TripleII | 08/23/07
dude you are paranoid multiple anti-whatever give me a break  SO.CAL Guy | 08/23/07
dude you are paranoid  aussieblnd@... | 08/23/07
Common sense doesn't work  TripleII | 08/23/07
Yep. Just because you're paranoid  RealTimer | 08/23/07
I lol'd  Bozzer | 08/28/07
hack thyself?  cwallen19803 | 08/23/07
Yup..  Wolfie2K3 | 08/23/07
Yes! I was thinking the same.  I am Gorby | 08/23/07
not just one anti anything  Adam Timmons | 08/23/07
Trend Micro Pin-cillin  zparagasjr | 08/23/07
Anti-virus protection  zparagasjr | 08/23/07
AVG  nhardin | 08/23/07
AVG - nhardin  eg.bremer@... | 08/24/07
Think about the assumptions in this claim  srkinyon | 08/23/07
But... But... But....  Wolfie2K3 | 08/23/07
Think about this ...  Jambalaya Breath | 08/24/07
I THINK THAT THIS SOFTWARE IS THE MILITARY  BALTHOR | 08/23/07
Uuuggghhh..."THE MILITARY"?  RealTimer | 08/23/07
Hacker safe SW  NightLife6 | 08/23/07
Zone Alarm  jon.h@... | 08/23/07
Re: ZA Access Control List  bart001fr | 08/27/07
7.0.362??  RS9 | 08/27/07
Issues so rare it is not worth worrying  masinick@... | 08/23/07
Secure Alternative Exists for Free!  mack68 | 08/24/07
Concentrate on app integrity, guys!  Vivek Nair | 08/24/07
THE MOST SUCCESSFUL MALWARE ATTACK IS THE ONE YOU DON'T KNOW ABOUT  BeanBagBlues | 08/24/07
Which paid AV do you use  steve@... | 08/26/07
What about MacAfee??  Sam404 | 08/25/07
Anti virus  bnmiller2 | 08/26/07
I have used several companies, they do this.  troubled241 | 08/29/07

What do you think?

SponsoredWhite Papers, Webcasts, and Downloads

advertisement

Recent Entries

Premier Vendor Content Whitepapers, webcasts & resources from our Power Center Sponsors
advertisement
Click Here

Archives

Favorite Links

ZDNet Blogs

White Papers, Webcasts, and Downloads