Symantec Norton Antivirus LiveUpdate Host Verification Vulnerability
BID:3403
Info
Symantec Norton Antivirus LiveUpdate Host Verification Vulnerability
| Bugtraq ID: | 3403 |
| Class: | Design Error |
| CVE: |
CVE-2001-1125 |
| Remote: | Yes |
| Local: | No |
| Published: | Oct 05 2001 12:00AM |
| Updated: | Jul 11 2009 07:56AM |
| Credit: | Discovered by FX <[email protected]>, DasIch <[email protected]> and kim0 <[email protected]> and published in a Symantec Security Response on October 5, 2001. |
| Vulnerable: |
Symantec LiveUpdate 1.5 Symantec LiveUpdate 1.4 |
| Not Vulnerable: |
Symantec LiveUpdate 1.6 |
Discussion
Symantec Norton Antivirus LiveUpdate Host Verification Vulnerability
Symantec's Norton Antivirus contains a feature called LiveUpdate. LiveUpdate is a process that checks for new virus definitions over the internet, downloads and installs them from a Symantec site. This process can either be scheduled or performed manually.
A flaw exists in Symantec's implementation of Norton Antivirus LiveUpdate, which fails to use Cryptography (Digital Signatures, Public Keys or Certificates) when performing LiveUpdates on a user's system. Therefore, it is possible for a remote host to send illicit LiveUpdates to an unknowing user.
Symantec's Norton Antivirus contains a feature called LiveUpdate. LiveUpdate is a process that checks for new virus definitions over the internet, downloads and installs them from a Symantec site. This process can either be scheduled or performed manually.
A flaw exists in Symantec's implementation of Norton Antivirus LiveUpdate, which fails to use Cryptography (Digital Signatures, Public Keys or Certificates) when performing LiveUpdates on a user's system. Therefore, it is possible for a remote host to send illicit LiveUpdates to an unknowing user.
Exploit / POC
Symantec Norton Antivirus LiveUpdate Host Verification Vulnerability
Phenoelit Group has a detailed example of exploitation in their advisory. The advisory can be found in the Credit section.
Currently the SecurityFocus staff are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Phenoelit Group has a detailed example of exploitation in their advisory. The advisory can be found in the Credit section.
Currently the SecurityFocus staff are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution / Fix
Symantec Norton Antivirus LiveUpdate Host Verification Vulnerability
Solution:
Symantec has acknowledged this issue and encourages users to upgrade to LiveUpdate 1.6. This updated version contains "cryptographic signatures" of all update files.
http://www.symantec.com/techsupp/files/lu/lu.html
Symantec's official response to this issue can be found at the following URL:
http://www.sarc.com/avcenter/security/Content/2001.10.05.html
Solution:
Symantec has acknowledged this issue and encourages users to upgrade to LiveUpdate 1.6. This updated version contains "cryptographic signatures" of all update files.
http://www.symantec.com/techsupp/files/lu/lu.html
Symantec's official response to this issue can be found at the following URL:
http://www.sarc.com/avcenter/security/Content/2001.10.05.html
References
Symantec Norton Antivirus LiveUpdate Host Verification Vulnerability
References:
References:
- Phenoelit Advisory
(Phenoelit Group) - Symantec LiveUpdate 1.4 through 1.6 vulnerability (Symantec)