According to rival Internet Security Systems' X-Force research group, which discovered the flaw, the bug is in the DEC2EXE module of the Symantec Antivirus Library, a part of the scanning engine that's able to peek into compressed executable files squeezed with the UPX (Ultimate Packer for eXecutables) format.Read more at InformationWeek
Symantec releases patch for critical security flaw

Symantec yesterday released patches for a vulnerability found in a wide range of its products, including BrightMail AntiSpam, AntiVirus Corporate Edition. On its website the company listed 29 of its products as vulnerable.