R E L A T E D   C O N T E N T

Free email newsletters




ADVERTISEMENT

Red-faced McAfee patches flaw in its security software

Anti-virus, anti-spyware and firewall programs could have leaked password

Marc Delehanty, Personal Computer World 03 Aug 2006
ADVERTISEMENT

McAfee has released an update for its Security Center software package to patch a security flaw that would have allowed attackers to obtain a user's password and other personal data.

Security firm eEye Digital Security announced the flaw last week, but released details to an embarassed McAfee beforehand and no attackers are believed to have exploited it.

The flaw relies on users loading a malicious web page, generated by an attacker, in Internet Explorer. The vulnerability in McAfee's software would then provide access to personal information.

The security patch will be automatically installed for users who have enabled updating in this way, otherwise it can be applied manually via the Security Center console.

Security Center contains McAfee's flagship products: Antispyware, Personal Firewall Plus, Virus Scan and ironically its Internet Security Suite.

eEye, founded in 1998, has a history of exposing flaws in popular software products including Microsoft's Internet Explorer and IIS web server.

See also:

EEye has engineered the patch to automatically remove itself when Microsoft's official patch comes throughWorkaround promises to protect browser in anticipation of official fix  28 Mar 2006
MicrosoftTime to download those updates again   15 Jun 2005
IIS has repeatedly been in the news for its poor security and kiddy friendly hacks. It's clear that relying on Microsoft and its patches is no longer good enough.  12 Sep 2001

All Bugs, Patches & Fixes

Like this story? Spread the news by clicking below:

Post this to Delicious del.icio.us    Post this to Digg Digg this    Post this to reddit reddit!

Permalink for this story
R E A D E R   C O M M E N T S

M A R K E T P L A C E
Sponsored links
F E A T U R E D   J O B S
Reading, Berkshire, United Kingdom | EDS
Position # 395423 Environment Manager Location - Reading, Berkshire Job Description: There is a requirement for an Environmental Manager for the Sandpits environment. This position is to act as the single point of contact for ... more >
Liverpool, United Kingdom | South Liverpool Housing Group
 Head of Information, Communication & Technology - £38,950 - £41,000 + benefits - Liverpool The SLH Group is a housing association responsible for 3,400 homes in Speke and Garston - two of Liverpool's most challenging ... more >
Central London, United Kingdom | MI5 Security Services
Messaging System Engineer - Competitive salaries + excellent benefits - Central London Getting the best out of technology is critical to helping us protect the UK. Join MI5 and use your skills and experience to help ... more >
Guildford, Surrey, United Kingdom | Enstar
 IT Development Manager/IT Development Project manager - Guildford - £40k - £60k plus benefits   Enstar (EU) Limited (formerly Castlewood (EU) Limited) is seeking an IT Development Project Manager and an IT Development Manager to ... more >
More job opportunities