Series of products hit by vulnerabilities

Posted by   Virus Bulletin on   Jul 25, 2007

Researcher finds flaws in ESET, Panda and Norman AV software.

Researcher Sergio Alvarez has reported on vulnerabilities found in a string of anti-virus products this week, with software ranges from ESET, Panda and Norman all hit by serious buffer-overflow flaws, allowing remote access if exploited.

The ESET problems involve the handling of CAB archives and files packed with ASpack, with NOD32 anti-virus systems for most platforms affected. Norman's issues also affect archive handling, in this case ACE and LZH, as well as DOC files, while the Panda overflows can be caused by specially crafted executables; again, multiple products from both vendors are affected.

All the vulnerabilities have been patched by recent updates, and users should be sure they are running fully up-to-date software to ensure they are protected. Summaries of the flaws at Secunia are here (ESET), here (Norman) and here (Panda), while more detailed descriptions of the discoveries are in the initial reports from Alvarez on

Posted on 25 July 2007 by Virus Bulletin



Latest posts:

$150k in cryptocurrency stolen through combined BGP-DNS hijack

A BGP hijack was used to take over some of Amazon's DNS infrastructure, which was then used to serve a phishing site to users of the MyEtherWallet service.

Security-focused routers may help to mitigate IoT threats

Various security companies are offering security-focused routers. This is a good trend and may help mitigate a lot of the issues that come with the IoT.

The road to IPv6 is generally smooth but contains a few potholes

Most of the switch from IPv4 to IPv6 will happen seamlessly. But we cannot assume it won't introduce new security issues.

New paper: Powering the distribution of Tesla stealer with PowerShell and VBA macros

Since their return four years ago, Office macros have been one of the most common ways to spread malware. Today, we publish a research paper which looks in detail at a campaign in which VBA macros are used to execute PowerShell code, which in turn…

VB2017 paper: Android reverse engineering tools: not the usual suspects

Within a few years, Android malware has grown from a relatively small threat to a huge problem involving more than three million new malware samples a year. Axelle Apvrille, one of the world's leading Android malware researchers, will deliver a…