Bad authentication breaks Symantec scanner

Email LinkedIn
Tools

Symantec's Scan Engine software contains three security bugs of its own, according to experts at research firm Rapid7. Scan Engine is a tool for embedding security software into third-party software, so this revelation could affect numerous other company's products. Symantec says there aren't known exploits, but Rapid7 says it's a very serious design flaw allowing remote attacks.

For more on the trouble:
- read this IDG News article

ALSO: RSA buys PassMark for $44 million. Article

PLUS: Yet another zero-day smacks IE. Article