Yale University

ITS Office of Information Security

Yale ITS Home Information Security

Gateways for:

Help Desk
203.432.9000
203.785.3200

ITS Office
Yale University
175 Whitney Avenue
P.O. Box 208276
New Haven, CT
06520-8276
USA

Yale logo.

Symantec AntiVirus Corporate Edition (SAV-CE) Vulnerability
Windows Only

Overview

A vulnerability exists that may allow a remote, unauthenticated attacker to execute malicious code. Exploiting this vulnerability can be accomplished without the user's knowledge or interaction.

Affected Software

  • Symantec Antivirus 10 version 10 and above
    [NOTE: Symantec Client Security 3.x is also affected, but this is not a University supported software package

Unaffected Software

  • Symantec AntiVirus Corporate Edition 8.0, 8.1, 9.0 all programs (builds)
  • Norton AntiVirus: No products in the Norton product line are affecte

Solution: Upgrade and/or patch your software to protect against potential related attacks. You must be running a current version of SAV for which Symantec has provided a patch.

  • If you are running the SAV 10.x client (either UNmanaged or Managed):
    1. Check to see which Program (build) of SAV 10 you are running by clicking on the Symantec shield icon in your task bar or by choosing Start > Programs > Symantec Client Security > Symantec AntiVirus. This will bring up a window that allows you to view the build number which is in the center under Program Version. In the picture below the build is 10.0.1.1000

    2. Choose the appropriate patch for your specific build from the table below. For example, if you are currently running Program (Build) 10.0.1.1000, you would apply patch 10.0.1.1001.

      Version Program(Build) Apply this Patch
      10.110.1.0.39410.1.0.396
      10.110.1.0.40010.1.0.401
      10.110.1.0.394 64 bit10.1.0.396
      10.010.0.2.200010.0.2.2002
      10.010.0.2.200110.0.2.2002
      10.010.0.2.201010.0.2.2011
      10.010.0.2.202010.0.2.2021
      10.010.0.1.100710.0.1.1009
      10.010.0.1.100010.0.1.1001

      Once you have downloaded the patch, you must double click the downloaded file and follow the instructions in order to finish the patching process.

    3. If you do not see your version number in the table above, you will need to upgrade your version of SAV. Symantec has not provided patches for all SAV 10 programs (builds). If you are running a program (build) of SAV 10 for which there is not a patch you need to upgrade to the current version of SAV 10 from the software library. Once you have upgraded to that new version the computer will be patched.

If you need assistance please contact the Help Desk (785.3200 or 432.9000).

Additional information:

Jump to top.

Last modified: Wednesday, 03-Oct-2007 15:46:01 EDT. (vm)