Panda Antivirus EXE File Parsing Buffer Overflow Vulnerability

ERCOLINO

Membro dello Staff
Amministratore
Registrato
3 Marzo 2003
Messaggi
252.665
Località
Torino
Secunia Advisory: SA26171
Release Date: 2007-07-23

Critical: Highly critical
Impact: System access
Where: From remote
Solution Status: Vendor Patch

Software: Panda AntiVirus Enterprise Suite
Panda AntiVirus Platinum 6.x
Panda AntiVirus Platinum 7.x
Panda AntiVirus Small Business Edition
Panda AntiVirus Titanium




Description:
Sergio Alvarez has reported a vulnerability in Panda Antivirus, which can be exploited by malicious people to compromise a vulnerable system.

The vulnerability is caused due to a boundary error when parsing .EXE files and can be exploited to cause a buffer overflow when e.g. scanning a specially crafted .EXE file.

Successful exploitation allows execution of arbitrary code.

Solution:
An update has reportedly been issued on 2007-07-20 through the regular update mechanism.



Bollettino Secunai
 
Indietro
Alto Basso