Secunia: CA backup product 'inherently insecure'

By Tom Espiner, ZDNet UK
Thursday, January 17, 2008 10:48 AM

Some CA products containing antivirus components have "inherent code problems", according to vulnerability-testing company Secunia, which published its annual report on security vulnerabilities this week.

One CA product particularly criticized by Secunia was ARCserve Backup, which the security company said was poorly coded.

"ARCserve is inherently insecure," Thomas Kristensen, Secunia's chief technology officer, told ZDNet.co.uk on Tuesday. "It's poor code, with a poor design. An internal code review should have revealed problems in the code that needed to be fixed before the product was launched."

In a statement sent to ZDNet.co.uk, CA said that it was improving its quality-assurance procedures.

"CA takes software security very seriously," said the statement. "CA works continuously to prevent and proactively identify and address vulnerabilities. We have rigorous quality-control measures in place for our software, and we continue to improve those measures."

ARCserve Backup, a CA data-protection product with in-built antivirus and encryption functionality, had multiple vulnerabilities reported in June 2007, said Secunia. These included flaws which could have led to stack-based buffer overflows, enabling attackers to compromise systems, according to a Secunia advisory.

Those errors were reported to CA, which pushed out a patch that fixed some of the code problems, said Secunia.

However, when Secunia researchers analyzed the patched product, they discovered that approximately 60 reported vulnerabilities were still present, according to the Secunia 2007 Report.

Secunia claimed its analysis revealed these vulnerabilities were partly due to the nature of the product code itself, and that vulnerabilities remain.

"Unless an overhaul of the code is undertaken, then the product remains susceptible to similar types of vulnerabilities," stated the report.

Thomas Kristensen said it was "surprising" to see 60 vulnerabilities in one product alone, but that it was more surprising that a patched product contained some of the same vulnerabilities, especially as it was patched by a security vendor.

"It's bizarre to see a patched product with vulnerabilities coming from a security vendor," said Kristensen. "It's not very smart to have vulnerabilities in a backup solution, as it's deployed on every workstation on a system, making the system more vulnerable."

CA declined to comment on how effective its ARCserve patch had been.

Security vendor Symantec was also criticized in the Secunia report, for its use of the third-party Autonomy KeyView software development kit in Symantec Mail Security.

According to a Secunia advisory, Autonomy KeyView, which is used in Symantec Mail Security as a Lotus 1-2-3 file viewer, can be exploited to cause buffer overflows when a specially crafted file is checked. Labelled "highly critical" by Secunia, the flaw could allow remote execution of arbitrary code.

Although the issue was reported on 12 December, the vulnerability remains unpatched, according to Secunia. Kristensen said that the problem faced by Symantec was that it was reliant on a third party to provide a patch.

"Vendors buy software from third parties to add functionality. The problem with KeyView is, it is third-party software [that] Symantec can't control--they rely on someone else to get the update, " said Kristensen.

Kristensen added that there does not seem to be a well-established communication channel between Symantec, Autonomy and IBM, which is also affected.

"Ideally IBM, Symantec and Autonomy would push out patches on the same day," said Kristensen.

Symantec said that its product-security team "has identified an issue with a third-party component that is included in some versions of Symantec Mail Security". The company added that it is working on a solution.

"Because we take the security of our products very seriously, we published detailed mitigation instructions to protect customers immediately and have subsequently issued product updates [for some of the vendors affected] as well," said Wayne Periman, director of development for Symantec Security Response.


WORTHWHILE?

0

0 votes
Blog

Talkback 0 comments

There are currently no comments for this post.


Tech Jobs Now!

Search for your ideal tech job:

Use shades of gray to enhance scale in Excel

Microsoft Office Suite

Excel's palette is generous, but don't throw buckets of pigment all over your spreadsheets just because you can.


Read more »



Ultimate 2012 recovery site: the moon

Blog thumbnail

Have you seen the disaster movie "2012"? A friend from Control Risks and I did, and we reluctantly concluded we wouldn't be able to write off the cost of our..... by Nathaniel Forbes

Read more »

Tags

  1. attack
  2. authentication and encryption
  3. blog
  4. data security
  5. e - mail
  6. hacking
  7. internet
  8. malware
  9. microsoft corp.
  10. network
  11. network security
  12. pc security
  13. researcher
  14. security
  15. security management
  16. software
  17. spam and phishing
  18. symantec corp.
  19. viruses and worms
  20. web