To avoid a security vulnerability

Jan 8, 2007 08:47 GMT  ·  By

Kaspersky Antivirus is one of the most popular antivirus solutions available on the market, with millions of users from the entire world attracted by the excellent results gained by the application in multiple tests. One of the most powerful features is represented by its engine and the detections tools that provide a high security rating for your computer. Even if this program is very efficient, many users reported that a full scan using Kaspersky can take from minutes to several hours, depending on the size of your hard-disks. So, the antivirus can assure your system's security, but the program itself is not safe in the front of a huge number of threats. This fact is sustained by a new vulnerability discovered in Kaspersky that can allow an attacker to control your computer.

Security company Secunia rated the flaw as moderately critical and said that the affected versions of the application are Kaspersky Anti-Virus 4.x, Kaspersky Anti-Virus 5.x, Kaspersky Anti-Virus 6.x, Kaspersky Internet Security 6.x and Kaspersky SMTP Gateway 5.x.

"Remote exploitation of a DoS vulnerability in Kaspersky Lab's Antivirus could allow an attacker to cause a denial of service (DoS) condition. Kaspersky is vulnerable to a DoS condition when processing a specially crafted PE (portable executable) file. One of the headers in a PE file is the Optional Windows Header section. This section of the PE header contains information needed by the Windows linker and loader. An invalid value for the 'NumberOfRvaAndSizes' field will cause Kaspersky to repeatedly seek and read from the same section of the file in an endless loop," iDefense Labs said.

Both companies also mentioned that this isn't a reason to change your antivirus solution because a patch was already delivered through the auto-update feature available in all versions of the program. The latest version of the Kaspersky Antivirus was also tested by Softpedia and it is available as a free download HERE.