Flaw Found in 2006 McAfee Products

By Ed Oswald | Published August 1, 2006, 12:26 PM

A flaw in many of McAfee's security products could open up users to a data exposure risk, security firm eEye Digital Security warned late Monday. Among the programs affected are Internet Security Suite, SpamKiller, Privacy Service and Virus Scan Plus, although the 2007 versions, released Saturday, are immune.

McAfee has confirmed the flaws and is working on a fix, saying a patch would be delivered automatically to subscribers by midweek. No known attacks have been reported to be taking advantage of the vulnerability. Exploit code is not available on the Web, researchers said, thus it's likely no attacks would occur.

"A flaw exists in multiple McAfee consumer products that could allow an attacker the ability to execute arbitrary commands on the vulnerable systems," eEye warned in its advisory.

"This can lead to complete system compromise at which point an attacker could install trojans, modify/delete files, or perform any other activity as a normal logged on user would."

A similarly dangerous flaw was discovered by the firm in May affecting Symantec products. In that issue, after the vulnerability is exploited, a hacker gains access to the command shell and is able to perform just about any action. The hole was patched quickly by Symantec.

eEye had also detected a flaw in McAfee programs protecting business computers in mid-July. However, unlike the consumer vulnerability the issue had been already addressed. McAfee said it did not warn customers of that problem, leading to criticism last month.

Comments

I recall a Mcafee product used in about 1999. Never looked back. Will never consider it.

Score: 0

|

big ****ing suprise there right? Is there a company which sucks more than mcafee? PC_Tool sums it up nice :/

Score: 0

|

For it's features and reliability, it's decent enough. My main issue is with the massive amount of 'components' one has to deal with on an un-install (also the source of most of the bloat and resource usage).

If they were to consolidate these *components* into one application / service, they'd cut down on the uninstall nightmare and bloat, the resource usage would likely go down quite a bit as well. (No longer using 6 processes to get the job done of one.)

Norton I.S. is as bad, if not worse in this regard.

What we need is better control over the XP firewall and a decent corporate-approved app like NOD32 (Spyware / Virus / Threat Database AIO).

But take this with a grain of salt as it's coming from an admitted NOD32 fanboy. ;)

Score: 0

|

Flaw Found in 2006 McAfee Products

Aside from the bloat, horrible un-installs, and resource hogging?

Didn't think it could get much worse. ;)

Score: 0

|

Agreed.

Score: 0

|

Before it can tackle Windows, Chrome must leave Safari in the dust

It's a little browser with dreams of becoming a bigger operating system some day. But while it's chasing Microsoft's dreams, Chrome's tail is being chased by Apple.

Silverlight 3 goes live on Microsoft's servers

Microsoft's answer to Adobe's Flash is (unofficially) here, with prospects of higher-speed, higher-resolution video and for the first time, 3D.

Best Buy-brand TVs to get TiVo

A new alliance will place the retailer's own brand alongide the manufacturers, and could also lead to future partnerships on services.

Three Android phones on the way from T-Mobile in 2009

T-Mobile's myTouch 3G, launched Wednesday, will be followed by two more Android phones later this year, but neither of them will be HTC's Hero.

LTE still lacks a voice

The 4G Wireless standard that Verizon hopes to show off before this year is out is still at a loss for (spoken) words.

T-Mobile's strategy to combat Apple's iPhone with Android

With a trio of Android phones now in the pipeline for 2009, T-Mobile hopes to break the iPhone's emerging stranglehold.

EC's Reding: Government should act as broker for media downloads

If Internet media services don't step up and build an attractive way for users to start paying for downloads, a commissioner says, government may do the job instead.

Sony TVs get Netflix, still no PS3

Though it's coming in behind LG, Samsung, and Microsoft, Sony will begin to offer Netflix streaming, too.

Google Chrome OS: Too little, too early

Carmi Levy: Wide Angle Zoom Don't start the revolution just yet, says Carmi, who isn't so certain Chrome OS will be the "Windows Killer."

GAO pen test brings the hammer down on federal rent-a-cops

But are the computers to blame for the contract-guard fiasco at FPS?

What's Next: Chrome OS will have at least some friends in high places

Also: South Korea takes another round of DDoS abuse, and Neelie Kroes and Steve Ballmer may shake hands before she exits stage left.

Data sharing among online advertisers: Is sanity in sight?

Lockdown with Angela Gunn In the middle of a 15-page plea not to get regulated, a spark of smart thinking.

PST Recovery Software 12.0

July 9 - 11:34 PM ET

Unistal Data Recovery 12.08.06

July 9 - 11:09 PM ET

BKF Repair 3.0

July 9 - 10:54 PM ET

Vuze for Windows 4.2.0.4

July 9 - 6:26 PM ET

UltraVNC 1.0.6.4

July 9 - 6:05 PM ET

WildBit Viewer 5.5 Beta 3.0

July 9 - 5:44 PM ET