First published: Fri Nov 17 2006(Updated: )
Panda ActiveScan 5.53.00, and other versions before 5.54.01, allows remote attackers to (1) reboot the system using the Reinicializar method in the ActiveScan.1 ActiveX control, or (2) determine arbitrary file existence and size via the ObtenerTamano method in the PAVPZ.SOS.1 ActiveX control.
Credit: PSIRT-CNA@flexerasoftware.com
Affected Software | Affected Version | How to fix |
---|---|---|
Panda ActiveScan | =5.53.00 | |
Panda ActiveScan | =5.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2006-5966 is rated as a medium severity vulnerability due to its potential to allow remote attacks.
To fix CVE-2006-5966, upgrade Panda ActiveScan to version 5.54.01 or later.
CVE-2006-5966 exploits the Reinicializar method to reboot the system and the ObtenerTamano method to determine file existence and size.
Versions of Panda ActiveScan before 5.54.01, specifically 5.53.00 and 5.0, are affected by CVE-2006-5966.
Yes, remote attackers can exploit CVE-2006-5966 to reboot the system or check for file sizes.