MacDailyNews - Where Mac news comes first

 MacDailyNews Poll

5 Day Most Commented

Opinion Archive

Current Headlines

Latest Joy of Tech

  • Latest Joy of Tech!

MacNN

AppleInsider

Macworld UK

TUAW

MacRumors

Yahoo! Finance AAPL

iTunes Top 10 Albums

Mac OS X Downloads

Fri, Nov 21, 2008 - 09:21 AM EST  —  AAPL: 80.49 (0.00, +0%)  |  NASDAQ: 1316.12 (0.00, +0%)

‘Highly critical’ flaw in discovered in Symantec AntiVirus for Mac OS X
Wednesday, December 21, 2005 - 03:09 PM EST

"Secure OS X reports on a 'highly critical' flaw that has been discovered in Symantec's AntiVirus software for Mac OS X," MacFixIt reports. "The vulnerability occurs when AntiVirus is decompressing files compressed in the RAR format for scanning. When AntiVirus is performing this operation, it is susceptible to to multiple heap overflows allowing attackers complete control of the system(s) being protected."

Secure OS X reports:
"These vulnerabilities can be exploited remotely without user interaction in default configurations through common protocols such as SMTP. Successful exploitation of Symantec protected systems allows attackers unauthorized control of data and related privileges. It also provides leverage for further network compromise. Symantec implementations are likely vulnerable in their default configuration. In default configurations users are likely vulnerable regardless of whether they choose to open or read the email."

"The only solution at this point is to filter RAR archives at email or proxy gateways, or disable and uninstall Norton AntiVirus," MacFixIt reports. "Until further notice, we recommend that users uninstall AntiVirus."

More info, links, and uninstall instructions here.

Advertisements:
The New iPod with Video. The ultimate music & video experience on the go. From $299. Free shipping.
Connect iPod to your television set with the iPod AV Cable. Just $19.00.
The New iMac G5. Built-in camera and remote control. From $1299. Free shipping.
Apple USB Modem. Easily connect to the Internet using your dial-up service. $49.00.

Related MacDailyNews articles:
Why Symantec's 'scare tactics' don't worry Mac users - September 28, 2005
$500 bounty offered for proof of first Apple Mac OS X virus - September 27, 2005
Symantec details flaws in its antivirus software - March 30, 2005
Motley Fool writer: 'I'd be surprised if Symantec ever sells a single product to a Mac user again' - March 24, 2005
Symantec cries wolf with misplaced Mac OS X 'security' warning - March 23, 2005
Symantec's Mac OS X claims dismissed as nonsense, FUD - March 22, 2005
Symantec warns about Mac OS X security threat - March 21, 2005

  • Social Web
  • E-mail






Always -- Free ground shipping with orders over $50 at the Apple Store.

Reader Feedback: ( = registered)

Dec 21, 05 - 03:18 pm Comment from: giofoto

Doh! ohh

Dec 21, 05 - 03:19 pm Comment from: giofoto

Good thing I never bought the darn thing.

Dec 21, 05 - 03:20 pm Comment from: iNewt

PRECIOUS!!!!

Dec 21, 05 - 03:21 pm Comment from: Ace

ouch.... Symantec isn't gonna like that, or maybe they are. They're the ones claiming OSX is flawed. Well.... the software we trust isn't, so did this glitch come intetionally or not is my question.

Dec 21, 05 - 03:22 pm Comment from: only idiots

buy an antivirus program for mac.

fugging tools.

yeah, i'm talking to you.

Dec 21, 05 - 03:22 pm Comment from: TFrank

Putting that crap on your Mac, messes it up anyway.

Dec 21, 05 - 03:25 pm Comment from: John Pisani

We don't need their sh_t

Dec 21, 05 - 03:25 pm Comment from: Jeff

but there no viruses on the Mac ... I don't get it.

Dec 21, 05 - 03:27 pm Comment from: JJ

An OS without 1 virus.

An app to protect the 1 OS without a virus.

The app leaves a hole for viruses.

What irony.

Dec 21, 05 - 03:28 pm Comment from: Brian Allen

Run for the hills the sky is falling!

Dec 21, 05 - 03:30 pm Comment from: rich b

Another reason not to run anti-virus software on a mac.
Funny thought that a anti-virus software program would CREATE the problem.

Dec 21, 05 - 03:31 pm Comment from: mudflapper

That's just downright funny.

Dec 21, 05 - 03:34 pm Comment from: we're not gonna take it

NO

we aint gonna take it

we're not gonna take it...anymore1111111111111

Dec 21, 05 - 03:35 pm Comment from: Tera Patricks

Finally, someone puts a hot poker into Symantec.

"The only solution at this point is to filter RAR archives at email or proxy gateways, or disable and uninstall Norton AntiVirus," MacFixIt reports. "Until further notice, we recommend that users uninstall AntiVirus."

Funny. I've always recommended that user uninstall Norton AntiVirus. Unless they're running Windows. In that case, they should uninstall Windows.

Bwahahahah!

Tera Patricks
Mac360

**MDN's magic word "didnt" as in 'I didn't say that, did I?'

Dec 21, 05 - 03:38 pm Comment from: Harold

Who needs or uses anti-virus software on a Mac????

Dec 21, 05 - 03:49 pm Comment from: dogfriend

If you insist on using AV on a Mac, at least try ClamXAV. Its free (actually donationware) and open source. No conflict of interest.

The most insecure software you can run on OS X turns out to be NAV. You can't make this stuff up.

Dec 21, 05 - 03:50 pm Comment from: iDon't

I think that Symantec was trying to create a problem so that they could fix it. Be honest people! Where do you think all the viruses and fixes are coming? The truth is out there.

Dec 21, 05 - 04:07 pm Comment from: BuriedCaesar

Haven't used NAV in more than 2 years. Clearly, they've got problems.

Dec 21, 05 - 04:16 pm Comment from: scott

oh the irony

Dec 21, 05 - 04:21 pm Comment from: Shadowself

It's been a LONG way down from SUM for Symantec. Symantec is (or at least should be) pretty much irrelevant to any Mac user.

Dec 21, 05 - 04:34 pm Comment from: Dave H

Without wanting to make accusations, has anyone checked their Windows software to see whether similar holes are introduced?

Dec 21, 05 - 04:42 pm Comment from: French Intelligence (sic)

[French accent]

See? Do you seeeeeee? Do you see how easy it is to make you American Mac users flustered. We French would never have such problems. Why?

Because we are better than you.

It's very simple, really. You stoopid mouth-breathers are all alike. It does not matter from where you hail in your vast, corrupt excuse for a nation. You all eat your drive-thru food like de pigs that you are. You get whatever you deserve for using Macs and ridiculing Jerry Lewis.

So, go about your pathetic lives whilst we Frenchmen continue to leer at our women and suckle at ze teat of our government's largesse. Oh, what's that? Largesse? Yes, you say you don't know what that means? Of course you don't -- you're all stupid in-bred, flatulent American dogs. Now . . .

GIVE US BACK OUR STATUE OF LIBERTY!!!!!!!!

[/French accent]

Dec 21, 05 - 04:49 pm Comment from: AV understanding

Oh the things we Mac users do to save our blinded by Bill Gates friends.

The only reason we use any AV software on our macs at work is so those who send us the infected files from their windows machines aren't reinfected since they can't understand they must run their AV software at least 87 times a day.

We have a mixed lab environments where people are notrious for using a winblowz machine to create a document then go to the Mac lab to finish working on it. After that, it gets sent to some other person who insists that "Windows is better." Thus taking down our network because they unleash 500 million worms.

MDNMW == "twenty" as in the number of hours it takes to remove all the components of Norton AV for Mac. Stupid stuff is installed in just about every stinking folder it can write to.

Dec 21, 05 - 04:53 pm Comment from: MacMania

If you're running Mac OS X and go out and spend good money on $ymantec (or any other) <i>"antivirus" you deserve what you get!

I mean you're already getting reamed by $ymantec with their protection racket; you might as well get raped some more by the nefarious assholes on the 'net too.

MDN Word: "business" - Yea, I know it's only business nothing personal

raspberry

Dec 21, 05 - 05:37 pm Comment from: Mr. Reeee

Symantec Software SUCKS?

How can it be?

Dec 21, 05 - 06:19 pm Comment from: ron

Virusymantec.

MW --name---How do it know?

Dec 21, 05 - 06:33 pm Comment from: no mo' AV

I got Symantec Anti Virus for free from my university's computer resources. The only reason I got AV was out of consideration for PC users who I might forward an infected email to that would have been sent to me by another PC user in the first place. Since my consideration for PC users is actually pretty weak, I just uninstalled AV. You PC users are on your own.

Dec 21, 05 - 07:13 pm Comment from: Veronica

Why would Symantic make anti virus Software for a Mac in the first place? How many do they expect to sell?

Dec 21, 05 - 07:18 pm Comment from: dogfriend

"Why would Symantic make anti virus Software for a Mac in the first place? How many do they expect to sell?"

It has been suggested that Symantec is worried about losing business after MS gets into the AV business. They need to create new markets to make up for lost Windows business. They appear to be trying to create business on the Mac platform by spreading FUD about OS X.

Dec 21, 05 - 08:12 pm Comment from: Anger Monkey

one more reason to get AVG antivirus on any windows machine for free, or Clam AV for cross platform use. I never worry about sending anything to friends from my Powerbook, most everyone uses a service that already scans the emails for malware.

Dec 21, 05 - 08:29 pm Comment from: Rainy Day

Too funny! LOL

Guess they need to call it Symantec Virus software for MacOS X wink

Dec 21, 05 - 08:50 pm Comment from: steve

The complete absence of any comment from MDN made me laugh! There is nothing to say when reality is even more bizarre than could have been imagined!

Dec 21, 05 - 09:30 pm Comment from: Rainy Day

Headline: First Trojan for MacOS X
Subtitle: First piece of malware which is not free; requires purchase

Only $78.71 from Office Nation. Buy today and save! rolleyes

MW: million, as in “Million dollar ad”

Dec 21, 05 - 11:31 pm Comment from: skedule keeper

My anti-virus approach is this:

System Preferences
Software Update
Check for updates: Daily
Download important updates in the background
(and, once alerted to an update) Install

Also, when MDN or other news outlets inform me of software updates out there, I can initiate Software Update on my own if the daily check hasn't transpired yet.

*IF* there is virus number 1, I trust Apple over anyone else to provide the solution. They are the ones that are going to understand the problem, plug up the holes, issue an update, and render the virus dead the fastest. Anti-virus software can't protect against threats that are yet to be discovered.

Dec 21, 05 - 11:35 pm Comment from: dennis

An oh-so-rare case of TRUE IRONY!

Dec 22, 05 - 01:47 am Comment from: hagar57

I've heard somewhere that Norton is able to resolve a part of the problems it creates. That was for the disc tools, looks like it also applies for virus software.

Dec 23, 05 - 03:30 am Comment from: TheConfuzed1

Another reason not to worry about antivirus software on the Mac...

Reader feedback page 1 of 1 pages:

Always -- Free ground shipping with orders over $50 at the Apple Store.

Add Your Feedback:

Register or Login

Name:

Email: (optional)

Emoticons | Allowed HTML Tags

Remember my personal information   Notify me of follow-up comments?

Please enter the "MDN Magic Word" you see in the image below: