<?xml version="1.0" encoding="UTF-8"?>

<rss version="2.0" xmlns:blogChannel="http://backend.userland.com/blogChannelModule">

<channel>
<title>Kaspersky AV Products Remote Heap Overflow Vuln. in Security</title>
<link>http://www.dslreports.com/forum/r14494903</link>
<description></description>
<language>en</language>
<pubDate>Fri, 04 Dec 2009 08:48:32 EDT</pubDate>
<lastBuildDate>Fri, 04 Dec 2009 08:48:32 EDT</lastBuildDate>

<item>
<title>Re: Kaspersky AV Products Remote Heap Overflow Vul</title>
<link>http://www.dslreports.com/forum/remark,14523808</link>
<description><![CDATA[<A HREF="/useremail/u/1122322"><b>Don Pelotas</b></A> : <div class="bquote"><SMALL>said by  Mele20 <A HREF="/useremail/u/403861"><IMG SRC="http://i.dslr.net/bb/profile.gif" ALT="See Profile" BORDER=0 WIDTH=16 HEIGHT=11></A> :</SMALL><BR><BR>I assume KAV and KIS 6.0 beta are also immune?<br><br>Edit: Just proves me right. :) 4.5 is superior to 5.0 no matter how much many of you wish that wasn't so. 6.0 is great also (except for a GUI and pop ups so tiny that no one can read them) and NOTHING like the ill fated, poorly done 5.0. <br> </DIV>Actually bacause you feel this way does not mean it is so, for me 5.0 is clearly better and yes i use iStreams.:p;):D<br><br>Version 4.0-4.5 has also had issue's along the way as any AV have during it's lifetime, they get discovered and then they get fixed, in this case no user was at risk because it was covered via signatures before the disclosure and the patch available within 48 hours. Just for record i think they are all good (4.5, 5.0 6.0), they all have their advantages/disadvantages, 6.0/2006 does look very promissing with the proactive defense, but for some users who are not into computers there will be a learningcurve greater than with the very easy to configure 5.0, i foresee a busy time at the Kav forum when it is released.<br><br>I don't know if 2006 has the patch but i would assume it, even if it is a beta. You are covered via signatures if not.:)]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,14523808</guid>
<pubDate>Fri, 07 Oct 2005 09:15:36 EDT</pubDate>
</item>

<item>
<title>Re: Kaspersky AV Products Remote Heap Overflow Vul</title>
<link>http://www.dslreports.com/forum/remark,14523730</link>
<description><![CDATA[<A HREF="/useremail/u/367939"><b>mboy</b></A> : <div class="bquote"><SMALL>said by  Mele20 <A HREF="/useremail/u/403861"><IMG SRC="http://i.dslr.net/bb/profile.gif" ALT="See Profile" BORDER=0 WIDTH=16 HEIGHT=11></A> :</SMALL><BR><BR>I assume KAV and KIS 6.0 beta are also immune?<br><br>Edit: Just proves me right. :) 4.5 is superior to 5.0 no matter how much many of you wish that wasn't so. 6.0 is great also (except for a GUI and pop ups so tiny that no one can read them) and NOTHING like the ill fated, poorly done 5.0. <br> </DIV>Still trying claim you know something about computing huh?<br>You have certainly proved a # of things around here lately. I wouldn't call one of them "being right".]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,14523730</guid>
<pubDate>Fri, 07 Oct 2005 08:58:19 EDT</pubDate>
</item>

<item>
<title>Re: Kaspersky AV Products Remote Heap Overflow Vuln.</title>
<link>http://www.dslreports.com/forum/remark,14523727</link>
<description><![CDATA[<A HREF="/useremail/u/1122322"><b>Don Pelotas</b></A> : <div class="bquote"><SMALL>said by  GuruGuy <A HREF="/useremail/u/737689"><IMG SRC="http://i.dslr.net/bb/profile.gif" ALT="See Profile" BORDER=0 WIDTH=16 HEIGHT=11></A> :</SMALL><BR><BR>Don, do you ever sleep?<br><br>I see you posting in various forums night and day!  <br><br>Thanks for all of your KAV support.<br> </DIV>6-8 hour a day, but thanks for the kind words.;):)]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,14523727</guid>
<pubDate>Fri, 07 Oct 2005 08:56:15 EDT</pubDate>
</item>

<item>
<title>Re: Kaspersky AV Products Remote Heap Overflow Vul</title>
<link>http://www.dslreports.com/forum/remark,14523682</link>
<description><![CDATA[<A HREF="/useremail/u/403861"><b>Mele20</b></A> : I assume KAV and KIS 6.0 beta are also immune?<br><br>Edit: Just proves me right. :) 4.5 is superior to 5.0 no matter how much many of you wish that wasn't so. 6.0 is great also (except for a GUI and pop ups so tiny that no one can read them) and NOTHING like the ill fated, poorly done 5.0. ]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,14523682</guid>
<pubDate>Fri, 07 Oct 2005 08:43:47 EDT</pubDate>
</item>

<item>
<title>Re: Kaspersky AV Products Remote Heap Overflow Vul</title>
<link>http://www.dslreports.com/forum/remark,14523604</link>
<description><![CDATA[<A HREF="/useremail/u/139520"><b>cork1958</b></A> : <div class="bquote"><SMALL>said by  33591094 <A HREF="/useremail/u/723836"><IMG SRC="http://i.dslr.net/bb/profile.gif" ALT="See Profile" BORDER=0 WIDTH=16 HEIGHT=11></A> :</SMALL><br><br>According to Kaspersky, KAV version 4.5 is not affected...<br><br>&raquo;<A HREF="http://www.kaspersky.com/news?id=171512144" >www.kaspersky.com/news?id=171512144</A><br><br><BLOCKQUOTE><I>Importantly, version 4.5 of Kaspersky Lab's antivirus products is not affected by the vulnerability.</BLOCKQUOTE><br> </DIV>Yay!! :)<br><SMALL>--<br>Spread <A HREF="http://www.opera.com/download/">Free Opera.</A> Fastest browser on Earth or in Cyberspace!!</SMALL>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,14523604</guid>
<pubDate>Fri, 07 Oct 2005 08:23:43 EDT</pubDate>
</item>

<item>
<title>Re: Kaspersky AV Products Remote Heap Overflow Vuln.</title>
<link>http://www.dslreports.com/forum/remark,14523328</link>
<description><![CDATA[<A HREF="/useremail/u/737689"><b>GuruGuy</b></A> : Don, do you ever sleep?<br><br>I see you posting in various forums night and day!  <br><br>Thanks for all of your KAV support.<br><SMALL>--<br>GuruGuy</SMALL>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,14523328</guid>
<pubDate>Fri, 07 Oct 2005 06:51:36 EDT</pubDate>
</item>

<item>
<title>Re: Kaspersky AV Products Remote Heap Overflow Vuln.</title>
<link>http://www.dslreports.com/forum/remark,14523241</link>
<description><![CDATA[<A HREF="/useremail/u/1122322"><b>Don Pelotas</b></A> : <div class="bquote"><SMALL>said by  IGGY <A HREF="/useremail/u/357201"><IMG SRC="http://i.dslr.net/bb/profile.gif" ALT="See Profile" BORDER=0 WIDTH=16 HEIGHT=11></A> :</SMALL><BR><BR> And on a little different note. It would nice if Kaspersky included a way to backup current settings. Similar to how ZoneLabs does things with ZoneAlarm. So that every time users are having to install a new build. They aren't having to go reset each and every option.<br></DIV>Already does, look for "Managing profiles" in the settings.;)<br><br>About updating the program, yes i can certainly see why this is appealing to many users, i personally would turn it of because i always wait a little while before any new version of any program is installed to avoid possible screwups with new builds.<br><br>Why do everybody in this thread who feels this is necessary not simply write Kaspersky and demand autoupdate a possibility in the future so that they will know about your wishes, a place you could use is the "Suggestions for current & future versions of KL products" at the official forum:&raquo;<A HREF="http://forum.kaspersky.com/" >forum.kaspersky.com/</A>, the more who suggests this, the greater the chance is that this will made possible.:)]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,14523241</guid>
<pubDate>Fri, 07 Oct 2005 06:06:54 EDT</pubDate>
</item>

<item>
<title>Re: Kaspersky AV Products Remote Heap Overflow Vul</title>
<link>http://www.dslreports.com/forum/remark,14522669</link>
<description><![CDATA[<A HREF="/useremail/u/879997"><b>dadkins</b></A> : <div class="bquote"><SMALL>said by  Anonymous <A HREF="/useremail/u/1016963"><IMG SRC="http://i.dslr.net/bb/profile.gif" ALT="See Profile" BORDER=0 WIDTH=16 HEIGHT=11></A> :</SMALL><br><br><div class="bquote"><SMALL>said by  dadkins <A HREF="/useremail/u/879997"><IMG SRC="http://i.dslr.net/bb/profile.gif" ALT="See Profile" BORDER=0 WIDTH=16 HEIGHT=11></A>  :</SMALL><br><br><div class="bquote"><SMALL>said by  33591094 <A HREF="/useremail/u/723836"><IMG SRC="http://i.dslr.net/bb/profile.gif" ALT="See Profile" BORDER=0 WIDTH=16 HEIGHT=11></A> :</SMALL><br><br>According to Kaspersky, KAV version 4.5 is not affected...<br><br>&raquo;<A HREF="http://www.kaspersky.com/news?id=171512144" >www.kaspersky.com/news?id=171512144</A><br><br><BLOCKQUOTE><I>Importantly, version 4.5 of Kaspersky Lab's antivirus products is not affected by the vulnerability.,/I><BLOCKQUOTE><br> </DIV>;):)<br> </DIV>Hmmm...why don't you update that old thing?<br>:p<br> </DIV>Well, seeing as it's not affected by this, and I don't have to patch it... why? ;)<br><SMALL>--<br>Think outside the Fox... <A HREF="http://www.opera.com/">Opera</A></SMALL>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,14522669</guid>
<pubDate>Fri, 07 Oct 2005 00:45:04 EDT</pubDate>
</item>

<item>
<title>Re: Kaspersky AV Products Remote Heap Overflow Vuln.</title>
<link>http://www.dslreports.com/forum/remark,14522473</link>
<description><![CDATA[<A HREF="/useremail/u/445404"><b>Martinus</b></A> : <div class="bquote"><SMALL>said by  the niTz <A HREF="/useremail/u/1035911"><IMG SRC="http://i.dslr.net/bb/profile.gif" ALT="See Profile" BORDER=0 WIDTH=16 HEIGHT=11></A> :</SMALL><br><br>what about kav for windows workstation does it download the update automatically cause im still seeing 5.0.177<br> </DIV>I downloaded it from here:<br><br>&raquo;<small>ftp</small>://<A HREF="ftp://ftp.avp.ru/updates50/AutoPatches/windows/">ftp.avp.ru/updates50/AutoPatches/windows/</A><br><br>It's called "patch_all_wks_5.0.225_to_5.0.227.exe", but you should probably update to 5.0.225 first.<br><SMALL>--<br>From the GSV "Ethics Gradient"</SMALL>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,14522473</guid>
<pubDate>Fri, 07 Oct 2005 00:03:33 EDT</pubDate>
</item>

<item>
<title>Re: Kaspersky AV Products Remote Heap Overflow Vuln.</title>
<link>http://www.dslreports.com/forum/remark,14522151</link>
<description><![CDATA[<A HREF="/useremail/u/357201"><b>IGGY</b></A> : But that will not alert you to newer builds of the product being available. Like most security software on the planet does within the update feature of the software. <br><br>I have my software setup exactly as you have stated. Yes you will get the patch - yes the patch should in fact update your current Kaspersky software to a newer build.<br><br>But if you were using a later build of the product your not going to be alerted to the fact that a newer build is available. So customers have to either be alerted in the &raquo;<A HREF="/forum/svendors">Security Product Vendors</A> forum. Which most people here honestly don't keep an eye on. Or the user has to get in the habit of checking the Kaspersky website from time to time. Which is something your average person just isn't going to do. <br><br>Although some would argue that in this case running an older Kaspersky build was a benefit. I've never felt running older builds of a security product is a wise thing. So anything that can be done to alert users to newer builds is a positive thing in my opinion.<br><SMALL>--<br><A HREF="http://test.iggyz.com">Test Your Security</A>    <A HREF="http://www.iggyz.com/AdvDiag.html">Cable Diagnostics</A><BR><A HREF="http://iggy.iggyz.com">My BLOG</A> <A HREF="http://zone.iggyz.com">ZoneAlarm Help</SMALL>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,14522151</guid>
<pubDate>Thu, 06 Oct 2005 23:16:53 EDT</pubDate>
</item>

<item>
<title>Re: Kaspersky AV Products Remote Heap Overflow Vul</title>
<link>http://www.dslreports.com/forum/remark,14522130</link>
<description><![CDATA[<A HREF="/useremail/u/1016963"><b>Anonymous</b></A> : <div class="bquote"><SMALL>said by  dadkins <A HREF="/useremail/u/879997"><IMG SRC="http://i.dslr.net/bb/profile.gif" ALT="See Profile" BORDER=0 WIDTH=16 HEIGHT=11></A> :</SMALL><BR><BR><div class="bquote"><SMALL>said by  33591094 <A HREF="/useremail/u/723836"><IMG SRC="http://i.dslr.net/bb/profile.gif" ALT="See Profile" BORDER=0 WIDTH=16 HEIGHT=11></A> :</SMALL><br><br>According to Kaspersky, KAV version 4.5 is not affected...<br><br>&raquo;<A HREF="http://www.kaspersky.com/news?id=171512144" >www.kaspersky.com/news?id=171512144</A><br><br><BLOCKQUOTE><I>Importantly, version 4.5 of Kaspersky Lab's antivirus products is not affected by the vulnerability.</BLOCKQUOTE><br> </DIV>;):)<br> </DIV>Hmmm...why don't you update that old thing?<br>:p]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,14522130</guid>
<pubDate>Thu, 06 Oct 2005 23:13:27 EDT</pubDate>
</item>

<item>
<title>Re: Kaspersky AV Products Remote Heap Overflow Vuln.</title>
<link>http://www.dslreports.com/forum/remark,14522036</link>
<description><![CDATA[<A HREF="/useremail/u/396697"><b>hamlet</b></A> : I may not be understanding the argument here Dogwood, but you can have KAV automatically update the version numbers.  If you go to "configure updater" and "updater settings", there is a box to check to enable automatic updating of the application module.  At least there is in my version 5.0 of KAV personal anti-virus.  It is true that you have to do an individual patch to correct this latest vulnerability, but, in general, you can configure KAV to automatically update the module.]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,14522036</guid>
<pubDate>Thu, 06 Oct 2005 22:59:15 EDT</pubDate>
</item>

<item>
<title>Re: Kaspersky AV Products Remote Heap Overflow Vuln.</title>
<link>http://www.dslreports.com/forum/remark,14520751</link>
<description><![CDATA[<A HREF="/useremail/u/737689"><b>GuruGuy</b></A> : ditto.........<br><SMALL>--<br>GuruGuy</SMALL>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,14520751</guid>
<pubDate>Thu, 06 Oct 2005 20:15:32 EDT</pubDate>
</item>

<item>
<title>Re: Kaspersky AV Products Remote Heap Overflow Vuln.</title>
<link>http://www.dslreports.com/forum/remark,14520622</link>
<description><![CDATA[<A HREF="/useremail/u/357201"><b>IGGY</b></A> : "And when they install it, they will update it and be protected."<br><br>Which isn't 100% true. Some users are clueless and might not in fact update the software right away. They should - but they may not.<br><br>As was mentioned above. A build with the patch applied should be available for download - especially for new users who would be testing a trial version or making a new purchase of Kaspersky.<br><br>And as I mentioned above. It would be nice if Kaspersky would finally add new version alerts to the updating system they currently use. That way users would have to go hunting every time they are wondering if a new build exist. <br><br>Just from reading this thread. It seems that Kaspersky might want to consider making things a little more obvious to it's customers. There seems to be a lot of confusing in this thread. Do to everyone using different builds and the large amount of builds that are available. <br><br>Kaspersky Anti-Virus Personal PRO 5.0.388: Corrected errors and enhancements<br><br>&raquo;<A HREF="http://www.kaspersky.com/faq?qid=168960104" >www.kaspersky.com/faq?qid=168960104</A><br><br>"the topic is about a critical fix, not update problems"<br><br>Actually when we have threads like this around here. We almost always discuss problems related to updating to the newer build or installing the update etc. within the update thread. So a post in regards to that would on topic in my opinion.<br><br>And on a little different note. It would nice if Kaspersky included a way to backup current settings. Similar to how ZoneLabs does things with ZoneAlarm. So that every time users are having to install a new build. They aren't having to go reset each and every option.<br><br>"Ok then, the KAV program will not automatically update like most every other AV program does through whole number versions."<br><br>The builds don't auto update. But the database definitions do. In the past users haven't been alerted to critical updates by using the update option in the software. And of course they haven't and still aren't alerted to newer builds being available from within the software.<br><br>Although I see this as something simple that should have been rectified ages ago. I honestly don't see it as a deal killer in regards to use of the product. The track record of the product outweighs this annoyance. <br><br>"Is there someplace or some way to download the patch again or do I have a bigger problem here?"<br><br>Try doing a full clean uninstall of the product. Have the latest version downloaded before doing this. Then reboot and make sure to stay offline. Install the new build and then reboot.<br><br>When you update the new build the patch should be downloaded and you should be alerted to install it.<br><br>You could also use the linked that was provided above to obtain the patch manually. My thought is you may need to do a clean install and you might also make sure you license is still valid. Although I doubt that is your problem.<br><SMALL>--<br><A HREF="http://test.iggyz.com">Test Your Security</A><br>    <A HREF="http://www.iggyz.com/AdvDiag.html">Cable Diagnostics</A><BR><A HREF="http://iggy.iggyz.com">My BLOG</A> <A HREF="http://zone.iggyz.com">ZoneAlarm Help</SMALL>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,14520622</guid>
<pubDate>Thu, 06 Oct 2005 19:55:54 EDT</pubDate>
</item>

<item>
<title>Re: Kaspersky AV Products Remote Heap Overflow Vuln.</title>
<link>http://www.dslreports.com/forum/remark,14520497</link>
<description><![CDATA[<A HREF="/useremail/u/302436"><b>wafen</b></A> : Don't know if I have a problem.<br>I downloaded the patch, I then restarted the computer.<br>When the computer rebooted I still have version 5.0.388 listed and not 5.0.390.<br>Is there someplace or some way to download the patch again or do I have a bigger problem here?<br><SMALL>--<br><A HREF="http://www.dslreports.com/forum/folding"><B>Join Team Helix!</B></A> <A HREF="http://www.stanford.edu/group/pandegroup/folding/"><B>Help Us Find A Cure!</A> <A HREF="http://www.dslreports.com/faq/thfaq">Get the FAQs!</A></B></SMALL>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,14520497</guid>
<pubDate>Thu, 06 Oct 2005 19:39:08 EDT</pubDate>
</item>

<item>
<title>Re: Kaspersky AV Products Remote Heap Overflow Vuln.</title>
<link>http://www.dslreports.com/forum/remark,14520486</link>
<description><![CDATA[<A HREF="/useremail/u/286744"><b>Dogwood</b></A> : Ok then, the KAV program will not automatically update like most every other AV program does through whole number versions.<br><br>That what I needed to know, now I will have to choose a different AV to install on PCs I build for customers.<br><br>Thanks for letting me know.<br><SMALL>--<br>Proud Member of: <A HREF="/forum/disco">Team Discovery</A> <BR> <A HREF="http://gaming.broadbandreports.com"><B>BroadbandGaming</B></A> <B>Admin</B> <BR> BBR Enemy Territory Clan Leader BBr|ET</SMALL>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,14520486</guid>
<pubDate>Thu, 06 Oct 2005 19:36:37 EDT</pubDate>
</item>

<item>
<title>Re: Kaspersky AV Products Remote Heap Overflow Vuln.</title>
<link>http://www.dslreports.com/forum/remark,14520446</link>
<description><![CDATA[<A HREF="/useremail/u/1035911"><b>the niTz</b></A> : what about kav for windows workstation does it download the update automatically cause im still seeing 5.0.177]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,14520446</guid>
<pubDate>Thu, 06 Oct 2005 19:29:08 EDT</pubDate>
</item>

<item>
<title>Re: Kaspersky AV Products Remote Heap Overflow Vul</title>
<link>http://www.dslreports.com/forum/remark,14520170</link>
<description><![CDATA[<A HREF="/useremail/u/886760"><b>no__1__here</b></A> : Except they don't list KAV Personal Pro there ;)]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,14520170</guid>
<pubDate>Thu, 06 Oct 2005 18:52:23 EDT</pubDate>
</item>

<item>
<title>Re: Kaspersky AV Products Remote Heap Overflow Vuln.</title>
<link>http://www.dslreports.com/forum/remark,14519952</link>
<description><![CDATA[<A HREF="/useremail/u/1122322"><b>Don Pelotas</b></A> : <div class="bquote"><SMALL>said by  Dogwood <A HREF="/useremail/u/286744"><IMG SRC="http://i.dslr.net/bb/profile.gif" ALT="See Profile" BORDER=0 WIDTH=16 HEIGHT=11></A>   :</SMALL><BR><BR>I guess the real question should be why did my copy of KAV not automatically update versions as they progressed, instead of staying at V5.0.227 for 8 months?<br> </DIV>Because you have not updated it.;)<br><br>You're mixing full programversions with this very small patch, if you want to to update the programversion from your version 5.0.277 to the latest version 5.0.388, you need to download the program from program updates:&raquo;<A HREF="http://www.kaspersky.com/productupdates" >www.kaspersky.com/productupdates</A> and install it in one of two ways: Either download the installer without databases (half the size because of the missing databases) and install ontop of existing installation or download the full version and uninstall 5.0.227 and install 5.0.388. I would do it with the second option.<br><br>The patch will be installed auto if you have "Update application modules" enabled in the updater settings (this exactly the situation this is for, installing patches) or you can install manually, you only have to this once no matter what version of 5.0 you are using, the version change from .372 to .375 or .388 to .390 is so you can see you have the patch, no other change than this small patch (64kb's if i remember correctly).]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,14519952</guid>
<pubDate>Thu, 06 Oct 2005 18:19:48 EDT</pubDate>
</item>

<item>
<title>Re: Kaspersky AV Products Remote Heap Overflow Vuln.</title>
<link>http://www.dslreports.com/forum/remark,14519900</link>
<description><![CDATA[<A HREF="/useremail/u/1159554"><b>norwegian</b></A> : dogwood<br><br>on the issue of the updating the versions, i can only gather that your are getting definition updates as you go, so you are updated.<br>now the software updates are a different matter, i can say, someone correct me if im not, <br><br>"That in order for software companies to diagnose problems for their users, prefer the latest install, purely for the simple fact, IF you get problems with the software, it helps eliminate most if not all past issues, so they as a company, can help the end user"<br><br>i can only see don doing the nessesary requirements to make the job easier, if we need a problem diagnosed<br><br>also, im not out to slander/ critize you either, so i will not comment anymore here, as this is Don Pelotas' turf<br>if you want to discuss it more, IM me about it,if the findings relate more on topic between us, it can be posted back here. the topic is about a critical fix, not update problems]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,14519900</guid>
<pubDate>Thu, 06 Oct 2005 18:14:06 EDT</pubDate>
</item>

<item>
<title>Re: Kaspersky AV Products Remote Heap Overflow Vuln.</title>
<link>http://www.dslreports.com/forum/remark,14519786</link>
<description><![CDATA[<A HREF="/useremail/u/286744"><b>Dogwood</b></A> : <div class="bquote"><SMALL>said by  norwegian <A HREF="/useremail/u/1159554"><IMG SRC="http://i.dslr.net/bb/profile.gif" ALT="See Profile" BORDER=0 WIDTH=16 HEIGHT=11></A> :</SMALL><br><br>dogwood, you dont read very well, it is mentioned it is an update that requires a reboot, whereas the normal updating doesnt need a reboot, where are you reading about uninstalling<br> </DIV>I read perfectly fine thank you very much!<br>I rebooted twice, once after the first patch file, then again after the second.<br>After the first patch, I had a V5.0.325, then after the second, I had V5.0.326, as I explained in my previous post, which you must not have read.<br><br>This is where I read about uninstalling:<br><div class="bquote"><SMALL>said by  Don Pelotas <A HREF="/useremail/u/1122322"><IMG SRC="http://i.dslr.net/bb/profile.gif" ALT="See Profile" BORDER=0 WIDTH=16 HEIGHT=11></A> :</SMALL><br><br>if you download the latest full version 5.0.388 <B>uninstall the one you have now</B> and install 5.0.388, then update your signatures and reboot after that, you then are at .390.<br> </DIV><div class="bquote"><SMALL>said by  norwegian <A HREF="/useremail/u/1159554"><IMG SRC="http://i.dslr.net/bb/profile.gif" ALT="See Profile" BORDER=0 WIDTH=16 HEIGHT=11></A> :</SMALL><br><br>don just suggested uninstall older versions if you have one and install ver 5.0.388, you can always ask someone to manually download the file if you dont want to get online before being fully updated<br> </DIV>Of course I know you must uninstall an AV program if you are going install a new one, but why is this necessary for just an update?<br><br><B>Is there not a patch to go from V5.0.326 to the latest version, or even the previous version?</B><br><br>I guess the real question should be why did my copy of KAV not automatically update versions as they progressed, instead of staying at V5.0.227 for 8 months?<br><SMALL>--<br>Proud Member of: <A HREF="/forum/disco">Team Discovery</A> <BR> <A HREF="http://gaming.broadbandreports.com"><B>BroadbandGaming</B></A> <B>Admin</B> <BR> BBR Enemy Territory Clan Leader BBr|ET</SMALL>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,14519786</guid>
<pubDate>Thu, 06 Oct 2005 17:55:12 EDT</pubDate>
</item>

<item>
<title>Re: Kaspersky AV Products Remote Heap Overflow Vuln.</title>
<link>http://www.dslreports.com/forum/remark,14519288</link>
<description><![CDATA[<A HREF="/useremail/u/1159554"><b>norwegian</b></A> : Dogwood and GuruGuy,<br><br>this has only been out a day, and as don says, its only a 60 kb update, if i remember correctly, they semi fixed via an update the same day it happened, but needed to test the real update for this before saying they have fixed it.<br>dogwood, you dont read very well, it is mentioned it is an update that requires a reboot, whereas the normal updating doesnt need a reboot, where are you reading about uninstalling<br><br>don just suggested uninstall older versions if you have one and install ver 5.0.388, you can always ask someone to manually download the file if you dont want to get online before being fully updated<br><br> <br>edit: it may be that they changed the version # as a cross reference to make sure people with KAV on are updating]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,14519288</guid>
<pubDate>Thu, 06 Oct 2005 16:41:42 EDT</pubDate>
</item>

<item>
<title>Re: Kaspersky AV Products Remote Heap Overflow Vuln.</title>
<link>http://www.dslreports.com/forum/remark,14519215</link>
<description><![CDATA[<A HREF="/useremail/u/737689"><b>GuruGuy</b></A> : That's exactly my point!<br><br>Why don't they just put the newest version on the download page so folks can download it and be done with it!<br><SMALL>--<br>GuruGuy</SMALL>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,14519215</guid>
<pubDate>Thu, 06 Oct 2005 16:31:30 EDT</pubDate>
</item>

<item>
<title>Re: Kaspersky AV Products Remote Heap Overflow Vul</title>
<link>http://www.dslreports.com/forum/remark,14519212</link>
<description><![CDATA[<A HREF="/useremail/u/286744"><b>Dogwood</b></A> : So there is no path to V5.0.390 from where I'm at, other than downloading a complete V5.0.388 install and doing the uninstall then reinstall BS?<br><br>I must be mistaken here, because that would be ridiculous.<br><SMALL>--<br>Proud Member of: <A HREF="/forum/disco">Team Discovery</A> <BR> <A HREF="http://gaming.broadbandreports.com"><B>BroadbandGaming</B></A> <B>Admin</B> <BR> BBR Enemy Territory Clan Leader BBr|ET</SMALL>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,14519212</guid>
<pubDate>Thu, 06 Oct 2005 16:30:52 EDT</pubDate>
</item>

<item>
<title>Re: Kaspersky AV Products Remote Heap Overflow Vul</title>
<link>http://www.dslreports.com/forum/remark,14519042</link>
<description><![CDATA[<A HREF="/useremail/u/1122322"><b>Don Pelotas</b></A> : You only have to apply the patch once to be fully patched for your version (whether it is 5.0.121, .142, .156, .227, .228, .325, .372, .383 or the latest 5.0.388), if you download the latest full version 5.0.388 uninstall the one you have now and install 5.0.388, then update your signatures and reboot after that, you then are at .390.]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,14519042</guid>
<pubDate>Thu, 06 Oct 2005 16:11:12 EDT</pubDate>
</item>

<item>
<title>Re: Kaspersky AV Products Remote Heap Overflow Vul</title>
<link>http://www.dslreports.com/forum/remark,14518967</link>
<description><![CDATA[<A HREF="/useremail/u/286744"><b>Dogwood</b></A> : OK, by installing the "patch_pers_5.0.121_142_149_156_227_228.exe" I was able to get to V5.0.325, then I ran the "patch_pers_5.0.325_to_5.0.326.exe" I got to V5.0.326.<br><br>[att=1]<br><br>Now where do I go to get to V5.0.390?<br>And why does KAV make updating so confusing?<br><SMALL>--<br>Proud Member of: <A HREF="/forum/disco">Team Discovery</A> <BR> <A HREF="http://gaming.broadbandreports.com"><B>BroadbandGaming</B></A> <B>Admin</B> <BR> BBR Enemy Territory Clan Leader BBr|ET</SMALL><div class="borderless"><TABLE WIDTH=95% align=center border=0 CELLPADDING=4"><TR><TD ALIGN=CENTER VALIGN=CENTER BGCOLOR=#000000 nwrap COLSPAN=3 WIDTH=100%><A HREF="/speak/slideshow/14518967?c=902957&ret=L2ZvcnVtL3IxNDQ5NDkwMy54bWw%3D"><IMG TITLE="76782 bytes" BORDER=0 WIDTH=589 HEIGHT=294 SRC="/r0/download/902957~4fd1a20c3bae174d4a3a5b7932de7e0c/KAV.jpg"></A></TD></TABLE></div>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,14518967</guid>
<pubDate>Thu, 06 Oct 2005 15:59:51 EDT</pubDate>
</item>

<item>
<title>Re: Kaspersky AV Products Remote Heap Overflow Vuln.</title>
<link>http://www.dslreports.com/forum/remark,14518939</link>
<description><![CDATA[<A HREF="/useremail/u/1122322"><b>Don Pelotas</b></A> : And when they install it, they will update it and be protected.]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,14518939</guid>
<pubDate>Thu, 06 Oct 2005 15:56:24 EDT</pubDate>
</item>

<item>
<title>Re: Kaspersky AV Products Remote Heap Overflow Vuln.</title>
<link>http://www.dslreports.com/forum/remark,14518875</link>
<description><![CDATA[<A HREF="/useremail/u/737689"><b>GuruGuy</b></A> : A person buying it at this moment is going to download the latest version.........if home, then he/she will download and install ver .388<br><br>That would be a vulnerable ver right from the start.  Why isn't the download area updated?<br><SMALL>--<br>GuruGuy</SMALL>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,14518875</guid>
<pubDate>Thu, 06 Oct 2005 15:46:41 EDT</pubDate>
</item>

<item>
<title>Re: Kaspersky AV Products Remote Heap Overflow Vul</title>
<link>http://www.dslreports.com/forum/remark,14518759</link>
<description><![CDATA[<A HREF="/useremail/u/0"><b>anon</b></A> : To clear up version number confusion see:<br>&raquo;<A HREF="http://www.kaspersky.com/faq?qid=171509522" >www.kaspersky.com/faq?qid=171509522</A><br><br>Basically to fix the .cab issue, one does not necessarily need build 390.<br><br>Latest builds to fix .CAB issue:<br># Kaspersky Anti-Virus Personal from 5.0.121 - 5.0.228 to 5.0.390<br># Kaspersky Anti-Virus Personal from 5.0.325 to 5.0.326<br># Kaspersky Anti-Virus Personal from 5.0.372 to 5.0.375<br># Kaspersky Anti-Virus Personal from 5.0.383 to 5.0.384<br># Kaspersky Anti-Virus Personal from 5.0.388 to 5.0.390<br><br># Kaspersky Anti-Virus Personal PRO from 5.0.372 to 5.0.375<br># Kaspersky Anti-Virus Personal PRO from 5.0.383 to 5.0.384<br># Kaspersky Anti-Virus Personal PRO from 5.0.388 to 5.0.390<br><br># Kaspersky Anti-Virus for Windows workstations from 5.0.225 to 5.0.227<br><br># Kaspersky Anti-Virus for Windows fileservers from 5.0.50 - 5.0.52 to 5.0.57 <br><br>If Autoupdate is not working, you may manually update from the following source:<br><br>&raquo;<small>ftp</small>://<A HREF="ftp://ftp.avp.ru/updates50/AutoPatches/windows/">ftp.avp.ru/updates50/AutoPatches/windows/</A>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,14518759</guid>
<pubDate>Thu, 06 Oct 2005 15:28:43 EDT</pubDate>
</item>

<item>
<title>Re: Kaspersky AV Products Remote Heap Overflow Vuln.</title>
<link>http://www.dslreports.com/forum/remark,14518601</link>
<description><![CDATA[<A HREF="/useremail/u/1122322"><b>Don Pelotas</b></A> : <div class="bquote"><SMALL>said by  GuruGuy <A HREF="/useremail/u/737689"><IMG SRC="http://i.dslr.net/bb/profile.gif" ALT="See Profile" BORDER=0 WIDTH=16 HEIGHT=11></A> :</SMALL><BR><BR>Why is there no .390 version available to download?  On the home products page, the most current available is still listed as .388<br> </DIV>Because the patch which makes 5.0.388 into 5.0.390 is only 60 something kb's & is applied via the updater or manual download via the link WFO supplied earlier in this thread.:)]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,14518601</guid>
<pubDate>Thu, 06 Oct 2005 15:03:45 EDT</pubDate>
</item>

<item>
<title>Re: Kaspersky AV Products Remote Heap Overflow Vuln.</title>
<link>http://www.dslreports.com/forum/remark,14518075</link>
<description><![CDATA[<A HREF="/useremail/u/737689"><b>GuruGuy</b></A> : Why is there no .390 version available to download?  On the home products page, the most current available is still listed as .388<br><SMALL>--<br>GuruGuy</SMALL>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,14518075</guid>
<pubDate>Thu, 06 Oct 2005 13:56:17 EDT</pubDate>
</item>

<item>
<title>Re: Kaspersky AV Products Remote Heap Overflow Vul</title>
<link>http://www.dslreports.com/forum/remark,14517947</link>
<description><![CDATA[<A HREF="/useremail/u/697604"><b>docchat</b></A> : <div class="bquote"><SMALL>said by  pc319 <A HREF="/useremail/u/621632"><IMG SRC="http://i.dslr.net/bb/profile.gif" ALT="See Profile" BORDER=0 WIDTH=16 HEIGHT=11></A> :</SMALL><BR><BR>Yep, same here.  KAV is now showing version 5.0.390<br> </DIV>Yep....mine also auto-updated yesterday and I just rebooted the computer to enable the new version.  <br><br>Doc]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,14517947</guid>
<pubDate>Thu, 06 Oct 2005 13:42:25 EDT</pubDate>
</item>

<item>
<title>Re: Kaspersky AV Products Remote Heap Overflow Vuln.</title>
<link>http://www.dslreports.com/forum/remark,14517929</link>
<description><![CDATA[<A HREF="/useremail/u/286744"><b>Dogwood</b></A> : Could someone please point me to the proper file to update my copy of KAV Personal V5.0.227 to the most current version?<br>TIA]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,14517929</guid>
<pubDate>Thu, 06 Oct 2005 13:40:33 EDT</pubDate>
</item>

<item>
<title>Re: Kaspersky AV Products Remote Heap Overflow Vul</title>
<link>http://www.dslreports.com/forum/remark,14517600</link>
<description><![CDATA[<A HREF="/useremail/u/545317"><b>Cabledude27</b></A> : Cool when I get home tonight I'll uninstall the suite and reinstall with the 1.1.53 thanks again!<br><SMALL>--<br>Your friendly neighborhood cabledude.</SMALL>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,14517600</guid>
<pubDate>Thu, 06 Oct 2005 12:53:23 EDT</pubDate>
</item>

<item>
<title>Re: Kaspersky AV Products Remote Heap Overflow Vul</title>
<link>http://www.dslreports.com/forum/remark,14517502</link>
<description><![CDATA[<A HREF="/useremail/u/1122322"><b>Don Pelotas</b></A> : <div class="bquote"><SMALL>said by  Cabledude27 <A HREF="/useremail/u/545317"><IMG SRC="http://i.dslr.net/bb/profile.gif" ALT="See Profile" BORDER=0 WIDTH=16 HEIGHT=11></A> :</SMALL><BR><BR>I use the KAV suite and it conflicts if I right click on the Icon and click about it gives me a lesser version than if I double click on the Icon and get the main gui.  Last check on opening the GUI it's .228 after a reboot.<br><br>If new upgrades are coming I'll just wait.  I was just wondering/concerned as I dont recall seeing many "product updates" and when I saw the various AV versions in the update field I wondered if something was amiss.<br> </DIV>I was wrong, just spoke with headquarters and there won't be new versions right now, so you might as well update like i described in my previous post, sorry about the confusion.:) ]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,14517502</guid>
<pubDate>Thu, 06 Oct 2005 12:39:29 EDT</pubDate>
</item>

<item>
<title>Re: Kaspersky AV Products Remote Heap Overflow Vul</title>
<link>http://www.dslreports.com/forum/remark,14517194</link>
<description><![CDATA[<A HREF="/useremail/u/1122322"><b>Don Pelotas</b></A> : <div class="bquote"><SMALL>said by  Cabledude27 <A HREF="/useremail/u/545317"><IMG SRC="http://i.dslr.net/bb/profile.gif" ALT="See Profile" BORDER=0 WIDTH=16 HEIGHT=11></A> :</SMALL><BR><BR>I use the KAV suite and it conflicts if I right click on the Icon and click about it gives me a lesser version than if I double click on the Icon and get the main gui.  Last check on opening the GUI it's .228 after a reboot.<br><br>If new upgrades are coming I'll just wait.  I was just wondering/concerned as I dont recall seeing many "product updates" and when I saw the various AV versions in the update field I wondered if something was amiss.<br> </DIV>Ok, your version of the suite is 1.0.22, the latest is called 1.1.53.:)]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,14517194</guid>
<pubDate>Thu, 06 Oct 2005 11:54:28 EDT</pubDate>
</item>

<item>
<title>Re: Kaspersky AV Products Remote Heap Overflow Vul</title>
<link>http://www.dslreports.com/forum/remark,14517048</link>
<description><![CDATA[<A HREF="/useremail/u/545317"><b>Cabledude27</b></A> : I use the KAV suite and it conflicts if I right click on the Icon and click about it gives me a lesser version than if I double click on the Icon and get the main gui.  Last check on opening the GUI it's .228 after a reboot.<br><br>If new upgrades are coming I'll just wait.  I was just wondering/concerned as I dont recall seeing many "product updates" and when I saw the various AV versions in the update field I wondered if something was amiss.<br><SMALL>--<br>Your friendly neighborhood cabledude.</SMALL>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,14517048</guid>
<pubDate>Thu, 06 Oct 2005 11:35:43 EDT</pubDate>
</item>

<item>
<title>Re: Kaspersky AV Products Remote Heap Overflow Vul</title>
<link>http://www.dslreports.com/forum/remark,14516912</link>
<description><![CDATA[<A HREF="/useremail/u/879997"><b>dadkins</b></A> : <div class="bquote"><SMALL>said by  33591094 <A HREF="/useremail/u/723836"><IMG SRC="http://i.dslr.net/bb/profile.gif" ALT="See Profile" BORDER=0 WIDTH=16 HEIGHT=11></A> :</SMALL><br><br>According to Kaspersky, KAV version 4.5 is not affected...<br><br>&raquo;<A HREF="http://www.kaspersky.com/news?id=171512144" >www.kaspersky.com/news?id=171512144</A><br><br><BLOCKQUOTE><I>Importantly, version 4.5 of Kaspersky Lab's antivirus products is not affected by the vulnerability.</BLOCKQUOTE><br> </DIV>;):)<br><SMALL>--<br>Think outside the Fox... <A HREF="http://www.opera.com/">Opera</A></SMALL>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,14516912</guid>
<pubDate>Thu, 06 Oct 2005 11:15:11 EDT</pubDate>
</item>

<item>
<title>Re: Kaspersky AV Products Remote Heap Overflow Vul</title>
<link>http://www.dslreports.com/forum/remark,14516461</link>
<description><![CDATA[<A HREF="/useremail/u/357201"><b>IGGY</b></A> : Which version of the product are you using? I think the build number may be different depending on which version of the product is being used. I could be wrong on this. But this is what I think we may be seeing.<br><br>After installing this update the other day. And after just rebooting my machine now. I need to update our other pc in the house. <br><br>My build number for Personal Pro is 5.0.357. Which is what it was after the update and before the reboot of the pc.<br><br>I need to check the website to see if a newer build actually exist later on today.<br><br>Honestly I've always felt the Kaspersky update system was lacking in regards to alerting customers / users of newer builds being available.<br><br>I do know the patch was downloaded in the update the other day. And I did select to have it install.<br><SMALL>--<br><A HREF="http://test.iggyz.com">Test Your Security</A>    <A HREF="http://www.iggyz.com/AdvDiag.html">Cable Diagnostics</A><BR><A HREF="http://iggy.iggyz.com">My BLOG</A> <A HREF="http://zone.iggyz.com">ZoneAlarm Help</SMALL>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,14516461</guid>
<pubDate>Thu, 06 Oct 2005 09:57:48 EDT</pubDate>
</item>

<item>
<title>Re: Kaspersky AV Products Remote Heap Overflow Vuln.</title>
<link>http://www.dslreports.com/forum/remark,14516454</link>
<description><![CDATA[<A HREF="/useremail/u/1122322"><b>Don Pelotas</b></A> : Yes, thats what i would do. You use the suite don't you, you must because 5.0.228 is the AV in the suite, you can download from here:&raquo;<A HREF="http://www.kaspersky.com/productupdates" >www.kaspersky.com/productupdates</A>, if i were you i would download the latest suite (not the technical release, thats for updating ontop of existing installation)and and also Kaspersky Personal 5.0.388 AV, then when you install the suite you deselect the AV and install 5.0.388 after having installed the suite, this way you're up to date with latest AV, FW, and antispam.<br><br>New versions are on the horizon and if you can wait a few days, then this might better for you, so you don't have to do the uninstall/reinstall dance again within a few days.  ]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,14516454</guid>
<pubDate>Thu, 06 Oct 2005 09:56:25 EDT</pubDate>
</item>

<item>
<title>Re: Kaspersky AV Products Remote Heap Overflow Vul</title>
<link>http://www.dslreports.com/forum/remark,14516322</link>
<description><![CDATA[<A HREF="/useremail/u/545317"><b>Cabledude27</b></A> : Thank's Don, I do have that option checked as well I did end up rebooting and nada.  I think something's up with it.  I have a valid license and all that, do you think uninstalling it and reinstalling it with the latest product download from the KAV site would resolve the issue?<br><SMALL>--<br>Your friendly neighborhood cabledude.</SMALL>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,14516322</guid>
<pubDate>Thu, 06 Oct 2005 09:30:24 EDT</pubDate>
</item>

<item>
<title>Re: Kaspersky AV Products Remote Heap Overflow Vul</title>
<link>http://www.dslreports.com/forum/remark,14515773</link>
<description><![CDATA[<A HREF="/useremail/u/1122322"><b>Don Pelotas</b></A> : You need to reboot after applying the patch. For the updater to download it, you need to have "Update application modules" checkmarked in the updatersettings.]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,14515773</guid>
<pubDate>Thu, 06 Oct 2005 07:08:08 EDT</pubDate>
</item>

<item>
<title>Re: Kaspersky AV Products Remote Heap Overflow Vul</title>
<link>http://www.dslreports.com/forum/remark,14513647</link>
<description><![CDATA[<A HREF="/useremail/u/545317"><b>Cabledude27</b></A> : Ok, I am not seeing how to get it from my version to the "updated" version.  When attempting to update it only updates the AV database.  I cant remember the last time it update the product.  I downloaded the patch_pers_5.0.121_142_149_156_227_228 version and now it says it's at 5.0.236 when I right click on the icon in the tray and click about.  When I double left click on the icon and the GUI comes up and I click the support tab it tells me I have 5.0.228.  <br><br>Help?!?! &#9;<br><SMALL>--<br>Your friendly neighborhood cabledude.</SMALL>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,14513647</guid>
<pubDate>Wed, 05 Oct 2005 21:49:07 EDT</pubDate>
</item>

<item>
<title>Re: Kaspersky AV Products Remote Heap Overflow Vul</title>
<link>http://www.dslreports.com/forum/remark,14513467</link>
<description><![CDATA[<A HREF="/useremail/u/461749"><b>WFO</b></A> : If for some reason anyone needs a manual download of the patch...<br><br>&raquo;<small>ftp</small>://<A HREF="ftp://ftp.avp.ru/updates50/AutoPatches/windows/">ftp.avp.ru/updates50/AutoPatches/windows/</A>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,14513467</guid>
<pubDate>Wed, 05 Oct 2005 21:28:51 EDT</pubDate>
</item>

<item>
<title>Re: Kaspersky AV Products Remote Heap Overflow Vul</title>
<link>http://www.dslreports.com/forum/remark,14509174</link>
<description><![CDATA[<A HREF="/useremail/u/621632"><b>pc319</b></A> : Yep, same here.  KAV is now showing version 5.0.390]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,14509174</guid>
<pubDate>Wed, 05 Oct 2005 11:09:45 EDT</pubDate>
</item>

<item>
<title>Re: Kaspersky AV Products Remote Heap Overflow Vul</title>
<link>http://www.dslreports.com/forum/remark,14509050</link>
<description><![CDATA[<A HREF="/useremail/u/658312"><b>danny9</b></A> : FYI<br>just received the fix a few minutes ago and installed.]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,14509050</guid>
<pubDate>Wed, 05 Oct 2005 10:52:19 EDT</pubDate>
</item>

<item>
<title>Re: Kaspersky AV Products Remote Heap Overflow Vul</title>
<link>http://www.dslreports.com/forum/remark,14508231</link>
<description><![CDATA[<A HREF="/useremail/u/723836"><b>33591094</b></A> : According to Kaspersky, KAV version 4.5 is not affected...<br><br>&raquo;<A HREF="http://www.kaspersky.com/news?id=171512144" >www.kaspersky.com/news?id=171512144</A><br><br><BLOCKQUOTE><I>Importantly, version 4.5 of Kaspersky Lab's antivirus products is not affected by the vulnerability.</BLOCKQUOTE>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,14508231</guid>
<pubDate>Wed, 05 Oct 2005 08:13:32 EDT</pubDate>
</item>

<item>
<title>Re: Kaspersky AV Products Remote Heap Overflow Vuln.</title>
<link>http://www.dslreports.com/forum/remark,14508078</link>
<description><![CDATA[<A HREF="/useremail/u/357201"><b>IGGY</b></A> : There is a response from the company on their site. CNET did an article on this yesterday. And I just added an article on the subject to my blog. As was mentioned above a fix is supposedly on the way. Kaspersky currently states that they feel this a minor threat.<br><br>This thread was linked in my original article in regards to this.<br><br>According to an article I just read and I'll be adding this information to my blog. Kaspersky has stated this issue has now been fully addressed.<br><SMALL>--<br><A HREF="http://test.iggyz.com">Test Your Security</A><br>    <A HREF="http://www.iggyz.com/AdvDiag.html">Cable Diagnostics</A><BR><A HREF="http://iggy.iggyz.com">Iggyz Blog</A> <A HREF="http://zone.iggyz.com">ZoneAlarm Help</SMALL>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,14508078</guid>
<pubDate>Wed, 05 Oct 2005 07:24:40 EDT</pubDate>
</item>

<item>
<title>Re: Kaspersky AV Products Remote Heap Overflow Vul</title>
<link>http://www.dslreports.com/forum/remark,14501030</link>
<description><![CDATA[<A HREF="/useremail/u/779741"><b>Khaine</b></A> : Fix is on the way:<br><br>&raquo;<A HREF="http://forum.kaspersky.com/index.php?showtopic=5014" >forum.kaspersky.com/index.php?showtopic=5014</A>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,14501030</guid>
<pubDate>Tue, 04 Oct 2005 09:27:37 EDT</pubDate>
</item>

<item>
<title>Kaspersky AV Products Remote Heap Overflow Vuln.</title>
<link>http://www.dslreports.com/forum/remark,14494903</link>
<description><![CDATA[<A HREF="/useremail/u/808823"><b>DonnaB</b></A> : Kaspersky Anti-Virus Products Remote Heap Overflow Vulnerability<br><br>A vulnerability has been identified in various Kaspersky Anti-Virus products, which could be exploited by attackers or malware to execute arbitrary commands. This issue is due to a heap overflow error in the CAB file format parser that does not properly handle a specially crafted file containing a malformed header, which could be exploited by attackers to execute arbitrary commands and compromise a vulnerable system (e.g. by sending an email containing a malicious CAB file).<br><br>Affected Products<br><br>Kaspersky Anti-Virus Library (cab.ppl) version 5.0.20.0 and prior<br>Kaspersky Anti-Virus 4.x<br>Kaspersky Anti-Virus 5.x<br>Kaspersky SMTP-Gateway 5.x<br><br>&raquo;<A HREF="http://www.frsirt.com/english/advisories/2005/1934" >www.frsirt.com/english/advisories/2005/1934</A> <br>&raquo;<A HREF="http://www.rem0te.com/public/images/kaspersky.pdf" >www.rem0te.com/public/images/kaspersky.pdf</A><br><SMALL>--<br><B>Microsoft MVP-Windows Security</B></BR><A HREF="http://www.a-sap.info"><B>Member of ASAP</B></A></BR><A HREF="http://cou.dozleng.com"><B>Calendar of Updates</B></A></BR><A HREF="http://msmvps.com/donna">SecurityFlash</A></SMALL>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,14494903</guid>
<pubDate>Mon, 03 Oct 2005 13:45:13 EDT</pubDate>
</item>

</channel>
</rss>
