Panda Remote Heap Overflow

2005.11.30
Risk: Low
Local: Yes
Remote: No
CWE: CWE-Other


CVSS Base Score: 7.5/10
Impact Subscore: 6.4/10
Exploitability Subscore: 10/10
Exploit range: Remote
Attack complexity: Low
Authentication: No required
Confidentiality impact: Partial
Integrity impact: Partial
Availability impact: Partial

Date November 29, 2005 Vulnerability The Panda Antivirus Library provides file format support for virus analysis. During decompression of ZOO files Panda is vulnerable to a heap overflow allowing attackers complete control of the system(s) being protected. This vulnerability can be exploited remotely without user interaction in default configurations through common protocols such as SMTP. Impact Successful exploitation of Panda protected systems allows attackers unauthorized control of data and related privileges. It also provides leverage for further network compromise. Panda implementations are likely vulnerable in their default configuration. Affected Products Due to the library??s modular design and core functionality: it is likely this vulnerability affects a substantial portion of Panda??s gateway, server, and client antivirus enabled product lines on most platforms. http://www.pandasoftware.com/ Note: this library is also licensed to other venders with implementations that are likely affected, refer to Panda for specifics. Details http://www.rem0te.com/public/images/panda.pdf Credit This vulnerability was discovered and researched by Alex Wheeler. Contact security (at) rem0te (dot) com [email concealed]


Vote for this issue:
50%
50%


 

Thanks for you vote!


 

Thanks for you comment!
Your message is in quarantine 48 hours.

Comment it here.


(*) - required fields.  
{{ x.nick }} | Date: {{ x.ux * 1000 | date:'yyyy-MM-dd' }} {{ x.ux * 1000 | date:'HH:mm' }} CET+1
{{ x.comment }}

Copyright 2024, cxsecurity.com

 

Back to Top