Panda Security ActiveScan 2.0 (Update) - Remote Buffer Overflow

Author: Karol Wiesek
type: remote
platform: windows
port: 
date_added: 2008-07-03  
date_updated:   
verified: 1  
codes: OSVDB-46740;CVE-2008-3156;OSVDB-46739;CVE-2008-3155  
tags:   
aliases: 2008-panda.tgz  
screenshot_url:   
application_url:   

raw file: 6004.txt  
Author:  	Karol Wiesek <karol [at] wiesek {dizd0t} pl>
Homepage:	http://karol.wiesek.pl/

There exists two vulnerabilities in Panda Security ActiveScan 2.0 Update function.
1) typical overflow ( this exploit )
2) Update function allows to install any ( attacker suplied ) CABinet into victims system

Panda Security have not respond in any manner, thus i have no information of any patches, plans for patching ...

* UPDATE *

Panda has patched newest version, so update will not connect to custom ( attacker supplied ) URL.

Exploit:
http://karol.wiesek.pl/files/panda.tgz
https://gitlab.com/exploit-database/exploitdb-bin-sploits/-/raw/main/bin-sploits/6004.tgz (2008-panda.tgz)

# milw0rm.com [2008-07-04]