Symantec fixes flaws in Norton, pcAnywhere

Article

Symantec fixes flaws in Norton, pcAnywhere

Bill Brenner, Senior News Writer
Symantec Corp. has fixed an ActiveX design flaw in its popular Norton AntiVirus software attackers could exploit to run malicious code on targeted machines. It also fixed a less serious flaw in a version of pcAnywhere that's no longer under active support.

The Cupertino, Calif.-based antivirus giant said

    Requires Free Membership to View

    SearchSecurity.com members gain immediate and unlimited access to breaking industry news, virus alerts, new hacker threats, highly focused security newsletters, and more -- all at no cost. Join me on SearchSecurity.com today!

    Michael S. Mimoso, Editorial Director

    By submitting your registration information to SearchSecurity.com you agree to receive email communications from TechTarget and TechTarget partners. We encourage you to read our Privacy Policy which contains important disclosures about how we collect and use your registration and other information. If you reside outside of the United States, by submitting this registration information you consent to having your personal data transferred to and processed in the United States. Your use of SearchSecurity.com is governed by our Terms of Use. You may contact us at webmaster@TechTarget.com.

a flaw in an ActiveX control used by Norton AntiVirus could potentially be exploited by a malicious Web site. An attacker could exploit the flaw to execute code remotely, the vendor said in an advisory.

A design error in NAVOPTS.DLL, the ActiveX control used in Norton AntiVirus, could potentially allow an attacker to crash the control if the user visits a malicious Web site. It "could then allow the attacker to access other Symantec ActiveX controls, even if they are not marked safe for scripting, possibly leading to remote arbitrary code execution in the context of the user's browser," the company added.

The flaw can only be exploited if an attacker tricks the user into visiting a malicious Web site.

"This type of attack is most commonly achieved through sending email containing a link to the malicious site, and persuading the recipient to click on the link," Symantec said.

Symantec has released a fix through its LiveUpdate program.

And though it's no longer a supported version, Symantec said it is preparing a fix for pcAnywhere version 11.5.0. The fix would be made available with no support available, Symantec said, adding that users who want full product support should upgrade to the latest version.

The problem with this version is that a remote user's connection credentials are stored in clear text within the Symantec pcAnywhere host server's process memory when a remote session is requested.

"The credentials of a remote user requesting a session connection can be compromised if a user with administration rights on the host machine utilizes tools to dump the process memory," Symantec said.