LinuxQuestions.org
Visit Jeremy's Blog.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Security
User Name
Password
Linux - Security This forum is for all security related questions.
Questions, tips, system compromises, firewalls, etc. are all included here.

Notices


Reply
  Search this Thread
Old 07-06-2016, 02:42 PM   #1
tronayne
Senior Member
 
Registered: Oct 2003
Location: Northeastern Michigan, where Carhartt is a Designer Label
Distribution: Slackware 32- & 64-bit Stable
Posts: 3,541

Rep: Reputation: 1065Reputation: 1065Reputation: 1065Reputation: 1065Reputation: 1065Reputation: 1065Reputation: 1065Reputation: 1065
US-CERT Alert (TA16-187A) Symantec and Norton Security Products Contain Critical Vulnerabilities


Not exactly Linux/Unix relevant but possibly important for any Windows systems you may support.

Systems Affected

All Symantec and Norton branded antivirus products

Overview

Symantec and Norton branded antivirus products contain multiple vulnerabilities. Some of these products are in widespread use throughout government and industry. Exploitation of these vulnerabilities could allow a remote attacker to take control of an affected system.
[List of 8 vulnerabilities]

Impact

The large number of products affected (24 products), across multiple platforms (OSX, Windows, and Linux), and the severity of these vulnerabilities (remote code execution at root or SYSTEM privilege) make this a very serious event. A remote, unauthenticated attacker may be able to run arbitrary code at root or SYSTEM privileges by taking advantage of these vulnerabilities. Some of the vulnerabilities require no user interaction and are network-aware, which could result in a wormable-event.

See the CERT Alert at https://www.us-cert.gov/ncas/alerts/TA16-187A for Solutions and References.

Hope this helps some.
 
Old 07-07-2016, 07:49 AM   #2
sundialsvcs
LQ Guru
 
Registered: Feb 2004
Location: SE Tennessee, USA
Distribution: Gentoo, LFS
Posts: 10,659
Blog Entries: 4

Rep: Reputation: 3941Reputation: 3941Reputation: 3941Reputation: 3941Reputation: 3941Reputation: 3941Reputation: 3941Reputation: 3941Reputation: 3941Reputation: 3941Reputation: 3941
This is a fundamental reason why I personally do not use any "anti-virus" Isic) product: anywhere, anytime.

These products, to me, are all "snake oil," based on the flawed assumption that computer systems are somehow "biological." That they can "get infected." That rogue software is "a virus." None of these things are true.

As a human being, you can "get sick" just by walking into an elevator in which someone else too-recently sneezed. Viruses can attach themselves to your DNA and therefore your body's immune system is constantly on the lookout, destroying them. "Sucks to be human," I guess ... ... but a computer is not that way.

"Anti-virus" software is extremely powerful and pervasive because it has access to everything in the system, and because it modifies files. It therefore is a very-obvious vector for attack. It has frequently been demonstrated that virus-signature files can be used to install rogue software.

But, speaking of "rogue software," this is also why I run every Internet ad-blocker I can find. Internet advertisements routinely consist of both images and code, and they have been used many times to launch DDOS attacks and other mischief. If you want millions of computers all around the world to be running your software, just conceal it in an advertisement . . .
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
US-CERT: Alert (TA16-144A) WPAD Name Collision Vulnerability Original release date: May 23, 2016 | Last revised: June 01, 2016 tronayne Linux - Security 0 06-03-2016 02:47 AM
US-Cert: Alert (TA16-144A) WPAD Name Collision Vulnerability tronayne Linux - Security 1 05-24-2016 03:48 PM
US-CERT: Alert (TA16-132A) Exploitation of SAP Business Applications tronayne Linux - Security 1 05-11-2016 12:11 PM
Alert (TA16-105A) Apple Ends Support for QuickTime for Windows; New Vulnerabilities Announced tronayne Linux - Security 4 04-18-2016 07:42 AM

LinuxQuestions.org > Forums > Linux Forums > Linux - Security

All times are GMT -5. The time now is 08:12 PM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration