Author Topic: bad news on heise.de  (Read 3452 times)

0 Members and 1 Guest are viewing this topic.

Karl S.

  • Guest
bad news on heise.de
« on: June 05, 2006, 12:48:14 PM »
http://www.heise.de/newsticker/meldung/73846

please you commentate.

thank you
Karl


ardvark

  • Guest
Re: bad news on heise.de
« Reply #1 on: June 05, 2006, 12:57:31 PM »
Hi Karl...

I'm afraid I can't comment on anything written in German  ::)
What is the jist?

Best Regards...

Karl S.

  • Guest
Re: bad news on heise.de
« Reply #2 on: June 05, 2006, 01:03:35 PM »
Oh, i´m shure you can read this webpage.
there you can find another adress:
http://www.frsirt.com/english/advisories/2006/2115
Karl

ardvark

  • Guest
Re: bad news on heise.de
« Reply #3 on: June 05, 2006, 01:11:17 PM »
Hi Karl...

Ah, much better :)

I can't comment on the particular flaw or any of the aspects concerning the coding, Vlk or Igor might be willing to address this the next time they log on.

However, a solution is listed and easily performed.

Best Regards...

Offline Vlk

  • Avast CEO
  • Serious Graphoman
  • *
  • Posts: 11658
  • Please don't send me IM's. Email only. Thx.
    • ALWIL Software
Re: bad news on heise.de
« Reply #4 on: June 05, 2006, 01:13:52 PM »
Well, there's not much we can say about that...

Here's the avast program history page
http://www.avast.com/eng/av4_revision_history.html


See the line
- temporarily disabled the CHM unpacker (for security reasons)

Seeing this line was enough for them to publish the above mentioned information (see the "Vulnerability reported by the vendor" note).


Anyway, the problem is there; it's in fact a Windows error - see http://secunia.com/advisories/20061 . Since avast uses this library, it (probably) has this error as well (well, not the error, but the consequences). So we decided to disable the CHM unpacker until the problem is sorted out by Microsoft (or we find a way to avoid it - which is not too likely though).


Hmm, this is how easy it is to generate some bad press... :-\

This sentence is completely unfair, and false: "Betroffene Anwender sollten daher erwägen, bis zur sauberen Fehlerbeseitigung durch Alwil auf einen anderen Virenscanner umzusteigen."


Cheers
Vlk
« Last Edit: June 05, 2006, 01:20:03 PM by Vlk »
If at first you don't succeed, then skydiving's not for you.

Offline RejZoR

  • Polymorphic Sheep
  • Serious Graphoman
  • *****
  • Posts: 9408
  • We are supersheep, resistance is futile!
    • RejZoR's Flock of Sheep
Re: bad news on heise.de
« Reply #5 on: June 05, 2006, 01:15:25 PM »
Of course they're aware of it, thats why they disabled CHM archives scanning, rather than leave it vulnerable. I'm sure they're working on it. CHM files aren't exactly super common, so there's really nothing to worry about.
Visit my webpage Angry Sheep Blog

hlecter

  • Guest
Re: bad news on heise.de
« Reply #6 on: June 05, 2006, 02:11:42 PM »
I read the Secunia Advisory pointed to by VLK.

I don't want to upgrade yet.

Would I be safe by putting chm files in exclusion-lists for now?
Or is there another workaround(other than upgrading.)?

Thanks
HL

Offline igor

  • Avast team
  • Serious Graphoman
  • *
  • Posts: 11855
    • AVAST Software
Re: bad news on heise.de
« Reply #7 on: June 05, 2006, 02:20:58 PM »
The exclusion list is not a solution - the file is recognized by content, not extension.
The only workaround, available in the Professional version of avast!, would be browse through all the tasks in Enhanced User Interface (especially the resident protection) and disable the CHM unpacker for all of them (and, not using Simple User Interface for archive scanning subsequently).
« Last Edit: June 05, 2006, 03:02:21 PM by igor »

hlecter

  • Guest
Re: bad news on heise.de
« Reply #8 on: June 05, 2006, 02:57:01 PM »
Thanks, Igor.