Description
Panda Global Protection 2010, Internet Security 2010, and Antivirus Pro 2010 use weak permissions (Everyone: Full Control) for the product files, which allows local users to gain privileges by replacing executables with Trojan horse programs.
Affected products
- pandasecurity / panda_antivirus2010 – 2010
- pandasecurity / panda_global_protection2010 – 2010
- pandasecurity / panda_internet_security2010 – 2010
References
- MISChttp://www.securitytracker.com/id?1023121
- VENDOR_ADVISORYhttp://secunia.com/advisories/37373
- MISChttps://exchange.xforce.ibmcloud.com/vulnerabilities/54268
- MISChttp://www.pandasecurity.com/homeusers/support/card?id=80164&idIdioma=2
- VENDOR_ADVISORYhttp://www.vupen.com/english/advisories/2009/3126
- MISChttp://www.securityfocus.com/archive/1/507811/100/0/threaded