iEntry 10th Anniversary RSS Archive

IT Management Begins With Security
SecurityProNews > News > Security News > ZoneAlarm Affected By Several Flaws
Search:
[ news_security_news ]

ZoneAlarm Affected By Several Flaws



David Utter
Staff Writer
2007-08-20

SecurityProNews: Insider Reports Insider Reports RSS Feed


Check Point Zone Labs was forced to patch a number of vulnerabilities with its products, including their firewall and anti-virus software.

Multiple input validation flaws as well as an insecure permission escalation problem with Zone Labs products required a series of fixes to correct.

iDefense Labs reported on those problems in a pair of advisories. In the privilege escalation scenario, local exploitation of the flaw could have led to disabling protection.

The default Access Control List settings have been blamed for this. "Some of the programs run as system services," said iDefense. "This allows a user to simply replace an installed ZoneAlarm file with their own code that will later be executed with system-level privileges."

Input validation problems could have permitted arbitrary code execution. "The problems specifically exist within the IOCTL handling code in the vsdatant.sys device driver," the advisory said.

If exploited, an attacker could gain complete control of the targeted machine. Existence of the problem has been confirmed in the widely used free version of the ZoneAlarm firewall product.

All of the vulnerabilities have been addressed by Check Point with updated products.



About the Author:
David Utter is a business and technology writer for SecurityProNews and WebProNews.

More news_security_news Articles

SecurityProNews: Insider Reports Insider Reports RSS Feed


Get Your Site Submitted for Free in the World's Largest B2B Directory!

Email Address:
* URL:
*
*Indicates Mandatory Field

Terms & Conditions

iEntry Featured Services: Jayde Member Services | Forums | Freeware | Advertise with Us

Virus Warnings

Subscribe to
SecurityProNews FREE!



[ more newsletters ]

article resources
Search Articles:
[advanced search]

WebProWorld.com
Get in-touch with industry experts and leaders
Post your site for review by expert and peers
Ask Security, IT, Development and Design questions

Free Membership: Join Now!

Visit WebProWorld.com

Titan Quest Forum
The #1 Titan Quest forum
Halo 3 Forum
The best Halo, Halo 2, Halo 3 forum
Nintendo Wii
Nintendo Wii news and views
Mac Software
The best in OS X freeware
Graphics Forum
Your source for graphic tutorials
SecurityProNews.com | Breaking eBusiness News Get Your IT Questions Answered - Click Here SecurityProNews News Feeds