ISS hit by major security hole

Security vendor Internet Security Systems Inc. (ISS) -- which describes itself as the "most trusted name in Internet security" -- has been hit by a critical hole in a common component of its security software that can allow someone to run programs on a machine over the Net.

The hole relates to the way ISS's products monitor ICQ server responses. A boundary error in the PAM (Protocol Analyses Module) component, regarding how it reads the SMB (Server Message Block) protocol, can be used to create a buffer overflow and so grant a remote malicious user complete control of a machine. It doesn't get any worse than that.

The PAM component is so basic that virtually all the company's products are affected, including the commonly used BlackICE security software, plus RealSecure and Proventia products. ISS, which was advised about the hole 10 days ago, have produced patches and upgrades for all its products and urges all customers to "immediately" download and install it.

The embarrassing hole was discovered by eEye Digital Security Inc. and ISS was informed of the problem on March 8. It developed the patches by March 18.

More about: eEye Digital Security, ICQ, Internet Security Systems, ISS, Security Systems

Comments

Post new comment

The content of this field is kept private and will not be shown publicly.
Users posting comments agree to the Computerworld comments policy.
Login or register to link comments to your user profile, or you may also post a comment without being logged in.
Related Whitepapers
Latest Stories
Community Comments
Whitepapers
All whitepapers
Sign up now to get free exclusive access to reports, research and invitation only events.
Featured Download
/downloads/product/58/seamonkey/

Seamonkey

Seamonkey includes an Internet browser, email and newsgroup client with an included web feed reader, HTML editor, IRC chat and web development tools. SeaMonkey will ...

Computerworld newsletter

Join the most dedicated community for IT managers, leaders and professionals in Australia