CVE-2005-3380: Medium severity Panda Titanium 2005 vulnerability
Multiple interpretation error in Panda Titanium 2005 4.02.01 allows remote attackers to bypass virus scanning via a file such as BAT, HTML, and EML with an "MZ" magic byte sequence which is normally associated with EXE, which causes the file to be treated as a safe type that could still be executed as a dangerous file type by applications on the end system, as demonstrated by a "triple headed" program that contains EXE, EML, and HTML content, aka the "magic byte bug."
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2005-3380?
CVE-2005-3380 has a medium severity rating as it allows attackers to bypass virus scanning.
How do I fix CVE-2005-3380?
To mitigate CVE-2005-3380, update to a patched version of Panda Titanium antivirus that addresses this vulnerability.
What software is affected by CVE-2005-3380?
CVE-2005-3380 affects Panda Titanium 2005 version 4.02.01.
What kind of files does CVE-2005-3380 allow to be executed?
CVE-2005-3380 allows files such as BAT, HTML, and EML to be executed as safe types due to the interpretation error.
What is the exploitation method for CVE-2005-3380?
Exploitation of CVE-2005-3380 occurs when a file with an 'MZ' magic byte sequence is treated as safe, bypassing virus scanning.