New Vulnerability in Symantec AntiVirus for MacintoshBest Security Tips offers daily news, information, advices and tips about spyware, adware, viruses, trojans, web vulnerabilities, hackers, other threats    | Register now | Login
   
TIPS NEWS TOOLS DOWNLOADS MALWARE FORUM BOOKS FREE MAGAZINES FREE WEBCASTS & VIDEOS
Internet security & monitoring for networks - Dld trial!  Bookmark and Share 
Best Tips
Security Scanner
Security Categories
Advertise With Us!
Latest Viruses / Threats
Our Partners
Downloads
Antivirus : New Vulnerability in Symantec AntiVirus for Macintosh
Posted by Max on 2007/11/4 9:40:45 (1198 reads)
Antivirus

A new vulnerability has been discovered in Symantec AntiVirus for Macintosh which may allow an user to run arbitrary code as root. An executable used by the Mount Scan feature of Symantec AntiVirus for Macintosh and Norton AntiVirus for Macintosh runs with root access. A member of group admin could replace this executable with code of their choice, and gain user root access.


The weakness is caused due to insecure permissions on the "/Library/Application Support" folder. This can be exploited to execute arbitrary code as the "root" user by e.g. replacing a certain application within the affected folder or tricking the Disk Mount scanner into launching an arbitrary executable by renaming folders.

Successful exploitation requires membership of the "admin" group and that "mount scanning" is enabled and configured to show the progress.

The weakness is reported in Norton AntiVirus for Macintosh 9.x-10.x, Norton Internet Security for Macintosh 3.x, Symantec AntiVirus for Macintosh 10.0 and 10.1. Linux and Windows versions are not affected.

Solution:
The vendor recommends to disable "Show Progress During Mount Scans" and to set the sticky bit for the folder "Library/Application Support" (see the vendor's advisory for details).

Best Practices
Symantec recommends any affected customers apply one of the mitigation steps to protect against potential attempts to exploit this issue. As part of normal best practices, Symantec also recommends the following:
  • Run under the principle of least privilege to limit the impact of potential exploits.
  • Restrict access to computer systems to trusted users only.
  • Keep all operating systems and applications updated with the latest vendor patches.
  • Follow a multi-layered approach to security. Run both firewall and antivirus software to provide multiple points of detection and protection from inbound and outbound threats.




Other articles
2010/3/18 8:07:31 - Panda Cloud Antivirus Receives ICSA Labs' First Cloud-Based Certification
2010/3/17 15:49:34 - Open-Source Email Security Taken To The Next Level at WebhostingDay
2010/3/17 15:18:40 - McAfee Warns ABout Scareware or Fake Antivirus Software
2010/3/2 5:22:13 - VeriSign and AVG Will Integrate VeriSign Trust(TM) Seal Within AVG LinkScanner(R)
2010/3/1 7:36:12 - New Stealth Software Protects P2P Users From Lawsuits by Copyright Holders
2010/2/24 13:55:16 - New State of The Art Firewall By Palo Alto Networks
2010/2/24 13:50:26 - Beware of Fake Antimalware Programs Like PCsProtector
2010/2/24 13:38:02 - New Registry Cleaner Guide Helps Your PC Perform Faster
2010/2/3 7:32:43 - PC Login Now (Full version) Available Now For Free.
2010/2/3 7:11:57 - Mitto Named One of 20 Top Web Applications

The comments are owned by the poster. We aren't responsible for their content.