SecurityReason.com - Our Reason is

Security

Register | Forget Password | Login
SecurityReason
WLB
Services
RSS
Corporate
Note

If you have found a vulnerability, please send to our SecurityAlert Database :
secalert()securityreason()com

Also if you have new ( 0-day ) exploit, please send to our ExploitAlert Archive :
exploit()securityreason()com

Home arrow SecurityAlert Database

Arrow  Topic :

Panda Remote Heap Overflow


Arrow  SecurityAlert : 216
Arrow  CVE : CVE-2005-3922
Arrow  SecurityRisk : Low  Security Risk Low  (About)
Arrow  Remote Exploit : No
Arrow  Local Exploit : Yes
Arrow  Exploit Available : No
Arrow  Credit : list rem0te com
Arrow  Published : 30.11.2005

Arrow  Affected Software : Panda Antivirus Library



Arrow  Advisory Content :  

Date
November 29, 2005

Vulnerability
The Panda Antivirus Library provides file format support for virus
analysis. During decompression of ZOO files Panda is vulnerable to a heap
overflow allowing attackers complete control of the system(s) being
protected. This vulnerability can be exploited remotely without user
interaction in default configurations through common protocols such as
SMTP.

Impact
Successful exploitation of Panda protected systems allows attackers
unauthorized control of data and related privileges. It also provides
leverage for further network compromise. Panda implementations are likely
vulnerable in their default configuration.

Affected Products
Due to the libraryâ??s modular design and core functionality: it is likely
this vulnerability affects a substantial portion of Pandaâ??s gateway,
server, and client antivirus enabled product lines on most platforms.

http://www.pandasoftware.com/

Note: this library is also licensed to other venders with implementations
that are likely affected, refer to Panda for specifics.

Details
http://www.rem0te.com/public/images/panda.pdf

Credit
This vulnerability was discovered and researched by Alex Wheeler.

Contact
security (at) rem0te (dot) com [email concealed]





Arrow  Feedback :

If you have additional information or notice any errors regarding this security advisory, please use contact form or email us at info()securityreason()com.
Alert

libc/fnmatch(3) DoS

Security Risk Medium- 2011-05-13

Allow attacker to denial of service apache 2.2.17 server

Apache RSS Apache Alert

» Apache HTTP Server Denial
   of Service Vulnerability

» Multiple Vendors
   libc/fnmatch(3) DoS (incl
   apache poc)

» Apache Continuum
   cross-site scripting
   vulnerability

» Apache Tomcat DoS
   Vulnerability

PHP RSS PHP Alert

» PHP Hashtables Denial of
   Service

» PHP 5.3.6 multiple null
   pointer dereference

» PHP 5.3.6 ZipArchive
   invalid use glob(3)

» libzip 0.9.3
   _zip_name_locate NULL
   Pointer Dereference (incl
   PHP 5.3.5)

ADT

Protect your family and valuables with Home Security Systems

Copyright © SecurityReason.com. All Rights Reserved.