« Fonts on web pages? | Main | Leopard' Server Gets Virtualization »

Symantec Discloses Weakness In Secuirty Software

The weakness is reported in Norton AntiVirus for Macintosh 9.x-10.x, Norton Internet Security for Macintosh 3.x, Symantec AntiVirus for Macintosh 10.0 and 10.1. Linux and Windows versions are not affected.

This weakness can be exploited by malicious, local users to gain escalated privileges.
It is caused due to insecure permissions on the "/Library/Application Support" folder. This can be exploited to execute arbitrary code as the "root" user by e.g. replacing a certain application within the affected folder or tricking the Disk Mount scanner into launching an arbitrary executable by renaming folders.

Since it requires local access, it shouldn't be very dangerous, but coming on the release of the porno trojan, it does show that Mac users need to be more vigilant than they have been.

See the announcement here.

------------------------------

Got News?

We'd love to hear about your news, software or hardware discoveries... just post at: our review input forms

del.icio.us del.icio.us... InfoManager RSS

------------------------------

Post a comment

(If you haven't left a comment here before, you may need to be approved by the site owner before your comment will appear. Until then, it won't appear on the entry. Thanks for waiting.)

Also see:

Affiliate & Supporting Sites

Get involved in your user group community

Please contact UGN... Submit Press Releases, Submit Full Articles, Send us your favorite links to resources, Submit Software Reviews, Submit Book Reviews, if you have a local user group, go here to register. UGNN is spam-free and will not share email addresses or your info with any third party. UGNN is paid for, in part, by: DT&G Online Magazine, the Design Bookshelf
The User Group Network is the first, and the original user group network for computer users everywhere including, Apple, Macintosh, IBM PC, Microsoft, Compaq, Amiga, BE/OS, Linux, UNIX, and other leading computer platforms. Hosting services are provided by The Graphic Design Network to serve the computing community. Copyright 1994 through present, all rights reserved. This site is hosted by The Graphic Design Network c/o Showker Graphic Arts & Design, a Corporation of the Commonwealth of Virginia, located in Harrisonburg Virginia, in the Shenandoah Valley of Virginia, established in 1972.

SPONSOR
 
Powered by
Movable Type 3.34