Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Beta Programs

Symantec Norton Antivirus LiveUpdate Host Verification Vulnerability

Symantec's Norton Antivirus contains a feature called LiveUpdate. LiveUpdate is a process that checks for new virus definitions over the internet, downloads and installs them from a Symantec site. This process can either be scheduled or performed manually.

A flaw exists in Symantec's implementation of Norton Antivirus LiveUpdate, which fails to use Cryptography (Digital Signatures, Public Keys or Certificates) when performing LiveUpdates on a user's system. Therefore, it is possible for a remote host to send illicit LiveUpdates to an unknowing user.







 

Privacy Statement
Copyright 2008, SecurityFocus