Falha Encontrada no Kaspersky Antivirus

Num mundo de vírus, spyware e bugs nada como estar informado

Moderadores: Administradores, Moderadores

Falha Encontrada no Kaspersky Antivirus

Mensagempor SuperMocho84 » Terça Out 04, 2005 11:54

Falha Encontrada no Kaspersky Antivirus

"Uma falha crítica no antivrius da Kasperksy Lab, pode deixar um utilizador mal intencionado ter controlo sobre os sistemas que tenham este produto instalado.

O problema encontra-se na base de dados dos virus. Esta falha deve afectar vários produtos da Kaspersky, visto que a base de dados é comum. Outros produtos que utilizem a tecnologia da Kaspersky poderão estar também vulneráveis.

O utilizador mal intencionado pode tomar o comando enviando um ficheiro CAB especificamente programado para aproveitar esta falha. O ficheiro pode ser enviado por e-mail e, uma vez aceite pelo antivirus, o código malicioso fica activo no sistema. Não é necessária interacção do utilizador.

Esta falha está definida como crítica, a pontuação mais elevada na escala utilizada."

Fonte: http://www.cdrwxp.co.pt/modules.php?op= ... =0&thold=0

Acontece aos melhores... :?
AMD Athlon64 3500+ Winchester
ASUS A8N-SLI Deluxe
ASUS Nvidia GeForce 6800GT 256MB DDR3
4x512MB DDR400 Kingston
Western Digital 250GB SATA II + 200GB SATA + 60GB IDE
Logitech X-230 + Audigy 2
Pioneer 120S + Optiarc 7173AD
LC Power Hyperion 700W
SuperMocho84
Membro Diamante
Membro Diamante
 
Mensagens: 1151
Registado: Terça Dez 21, 2004 11:48
Localização: Parede

Re: Falha Encontrada no Kaspersky Antivirus

Mensagempor PapaGigas » Terça Out 04, 2005 13:17

SuperMocho84 Escreveu:Acontece aos melhores... :?


Neste caso avalia-se a situação através do tempo de resposta após a descoberta da vulnerabilidade.. tic-tac.. tic-tac.. tic-tac.. :P
If I offended you in anyway, please don't take it personally... it's not your fault you're an idiot!
PapaGigas
Gurus
Gurus
 
Mensagens: 4337
Registado: Sexta Out 22, 2004 2:54
Localização: Marrocos

Mensagempor SuperMocho84 » Terça Out 04, 2005 14:11

Exacto. Vamos lá ver quanto tempo eles demoram a corrigir essa falha...
AMD Athlon64 3500+ Winchester
ASUS A8N-SLI Deluxe
ASUS Nvidia GeForce 6800GT 256MB DDR3
4x512MB DDR400 Kingston
Western Digital 250GB SATA II + 200GB SATA + 60GB IDE
Logitech X-230 + Audigy 2
Pioneer 120S + Optiarc 7173AD
LC Power Hyperion 700W
SuperMocho84
Membro Diamante
Membro Diamante
 
Mensagens: 1151
Registado: Terça Dez 21, 2004 11:48
Localização: Parede

Mensagempor PsicoPete » Terça Out 04, 2005 14:26

Código: Seleccionar todos
There has recently been a wide-ranging discussion in the mass media about a report by Alex Wheeler, an independent researcher, that a vulnerability related to processing files of the CAB format has been discovered in Kaspersky Lab antivirus products. Taking into account the close attention of the computer community, Kaspersky Lab considers it necessary to provide official comments on the incident.

The company confirms the presence of a vulnerability in a Kaspersky Anti-Virus module used to process CAB files. Taking advantage of this vulnerability results in a malfunction of the antivirus program. This effect is present only in the Windows environment and does not affect other operating systems.

At the same time, Kaspersky Lab specialists have taken measures to eliminate the threat related to the CAB module vulnerability. First of all, on receiving the relevant data, the virus analyst team within a short time period created a package of signatures that detect possible exploits of this vulnerability (procedures that use the vulnerability to compromise a computer). This set of signatures was added to the antivirus databases of Kaspersky Anti-Virus on September 29, significantly reducing the chances of successful use of the CAB vulnerability exploits. Furthermore, no attempts to create and distribute such exploits have been recorded to date. In this connection, it should be noted that Alex Wheeler, who discovered the vulnerability in question, has not provided demonstration code that uses it.

All in all, based on the above factors it can be stated that the actual threat posed by the CAB vulnerability is minimal and cannot affect the level of antivirus protection provided by Kaspersky Lab products.

Kaspersky Lab experts are currently developing an emergency update of the company's antivirus products which include the CAB module affected by the vulnerability. The revised list of such products includes: Kaspersky Anti-Virus Personal 5.0, Kaspersky Anti-Virus Personal Pro 5.0, Kaspersky Anti-Virus 5.0 for Windows Workstations, Kaspersky Anti-Virus 5.0 for Windows File Servers, Kaspersky Personal Security Suite 1.1. Importantly, version 4.5 of Kaspersky Lab's antivirus products is not affected by the vulnerability. Updates eliminating the CAB vulnerability for all the programs listed above will be released in the second half of October 5th, 2005 and will be available for installation using standard updating procedures.

Kaspersky Lab is also a known provider of antivirus solutions for OEM and technology partners. Majority of solutions distributed by Kaspersky Lab OEM and technology partners does not incorporate the vulnerable module and thus is not affected. Furthermore the signature database update released by Kaspersky Lab on 29th of September prevents potential attacks by detecting and neutralizing the malicious code of a possible exploit before system can be affected. This countermeasure provides necessary level of protection for potentially vulnerable systems until the software update is released.

04/10/05



Podem ver aqui -> http://www.kaspersky.com/news?id=171512144

Cumps.
Imagem
"Some men see things as they are and say why - I dream things that never were and say why not." - George Bernard Shaw
PsicoPete
Membro Vitalício
Membro Vitalício
 
Mensagens: 2389
Registado: Sábado Ago 14, 2004 12:22

Mensagempor winstroll » Quarta Out 05, 2005 16:34

boas

espero k tratem de isso rapido pq continua a ser o meu AV de eleiçao


saludos
Asus G1-AK005G
winstroll
Membro de Prata
Membro de Prata
 
Mensagens: 455
Registado: Sábado Fev 19, 2005 10:16

Mensagempor NePTeR » Sábado Out 08, 2005 10:09

Após ter sido verificada uma falha na segurança nos seus produtos, a empresa Russa, disponibilizou actualizações dos mesmos através do "auto-updater" incluido nos seus produtos.

As versões dos produtos afectadas e consequente actualização :

* Kaspersky Anti-Virus Personal
5.0.121 para 5.0.122
5.0.142 para 5.0.143
5.0.149 para 5.0.150
5.0.156 para 5.0.157
5.0.227 para 5.0.236
5.0.228 para 5.0.236
5.0.325 para 5.0.326
5.0.372 para 5.0.375
5.0.383 para 5.0.384
5.0.388 para 5.0.390

* Kaspersky Anti-Virus Personal Pro
5.0.372 para 5.0.375
5.0.383 para 5.0.384
5.0.388 para 5.0.390

* Kaspersky Anti-Virus 5.0 for Windows File Servers
5.0.50 - 5.0.52 para 5.0.57

* Kaspersky Anti-Virus 5.0 for Windows Workstations
5.0.225 para 5.0.227

fonte: cdrwxp
Imagem
NePTeR
Membro de Ouro
Membro de Ouro
 
Mensagens: 718
Registado: Sábado Jul 23, 2005 16:00
Localização: Planeta Terra

Mensagempor PapaGigas » Sábado Out 08, 2005 13:43

Eu sabia que eles não iam demorar muito a tratar desta situação (afinal de contas.. não se chamam Micro$oft.. LOL).. :lol: :lol: :lol:
If I offended you in anyway, please don't take it personally... it's not your fault you're an idiot!
PapaGigas
Gurus
Gurus
 
Mensagens: 4337
Registado: Sexta Out 22, 2004 2:54
Localização: Marrocos


Voltar para Segurança Informática

Quem está ligado:

Utilizadores a ver este Fórum: Nenhum utilizador registado e 0 visitantes

cron