Blog: Symantec

Engineers beware….enabling Symantec network scanning features of real-time protection will slow the network to a crawl. Symantec actually recommends turning off network scanning on Symantec v10.0 and below because of the severe performance impact it causes. In v10.1 and above, Symantec supposedly “improved” the network scanning functionality as well as introduced the ability to trust a server that was running real-time protection to prevent double scanning of a file. Unfortunately, the network scanning features don’t seemed to be improved in any way and the trust stuff looks to be all fluff. Additionally, after troubleshooting and testing it looks like when Symantec is configured to do network scans, instead of scanning the files on the client side as they traverse through the network stack, Symantec actually opens up literally hundreds of file handles to the files remotely and attempts to scan the on the share remotely on the share. This behavior has been verified to be the cause of several network performance issues at one of our customers lately.


 

Symantec has recently released information about a critical vulnerability found in their Client Security and AntiVirus Corporate Edition products that may allow local or remote attackers to crash a system or execute arbitrary code.

The following Symantec Client Security products are affected: [more]

  • v3.1 (build 3.1.0.394)
  • v3.1 (build 3.1.0.400)
  • v3.0 (build 3.0.2.2000)
  • v3.0 (build 3.0.2.2001)
  • v3.0 (build 3.0.2.2010)
  • v3.0 (build 3.0.2.2020)
The following Symantec Antivirus Corporate Edition products are affected:
  • v10.1 (build 10.1.0.396)
  • v10.1 (build 10.1.0.400)
  • v10.0 (build 10.0.2.2000)
  • v10.0 (build 10.0.2.2001)
  • v10.0 (build 10.0.2.2010)
  • v10.0 (build 10.0.2.2020)

Security patches to address affected products, as well as more information about this vulnerability can be obtained at:
http://www.symantec.com/avcenter/security/Content/2006.05.25.html