Ethical Hacking Learn to find vulnerabilities before the bad guys do! Gain real world hands on hacking experience in our state of the art hacking lab. Course designed and taught by expert instructors with years of penetration testing experience. 12 student maximum in every class. Certification attempt included in every package. | Computer Forensics Training at InfoSec Institute Gain the in-demand skills of a certified computer examiner, learn to recover trace data left behind by fraud, theft, and cybercrime perpetrators. Discover the source of computer crime and abuse at your organization so that it never happens again. All of our class sizes are guaranteed to be 12 students or less to facilitate one-on-one interaction with one of our expert instructors. |

| Subject: | Re: [Full-disclosure] Panda Antivirus 2008 Local Privileg Escalation (UPS they did it again) |
|---|---|
| Date: | Mon, 24 Sep 2007 09:48:19 +0200 |
-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1
-----Original message----- From: 3APA3A [mailto:3APA3A@SECURITY.NNOV.RU] secure@pandasoftware.com was contacted about this same vulnerability in Panda Antivirus 2007 on August, 11 2006 (more than year ago) without any results and response, until information was published in Bugtraq.
The vulnerability response team was created in 10/2006 to manage vulnerability reports and create fixes as necessary.
As far, as I can see, pandasecurity.com is Swedish domain of Panda while pandasoftware.com is international one. I believe it's quite reasonable to have secure@pandasoftware.com to be forwarded to secure@pandasecurity.com, don't you think so?
Re: secure@pandasoftware.com & secure@pandasecurity.com, it's the same contact mailbox at the Panda HQ domain in Spain (.es), not Sweden (.se). Public key attached. Regards, - ---------------------------------------------- Pedro Bustamante Senior Research Advisor Panda Security email: pedro.bustamante@pandasecurity.com <0xC684A6F9> vulns: secure@pandasecurity.com <0x70F3FEA0> phone: (+34) 91-8063700 blog: http://research.pandasoftware.com - ---------------------------------------------- -----BEGIN PGP SIGNATURE----- Version: PGP 8.1 iQA/AwUBRvdrw46s6aZw8/6gEQJ+bACfWyLJHFMarDWRU1h/sbD7xttIUmkAoO2W lMvAKwSZDMPuCx7yCnEFnQ+y =wLME -----END PGP SIGNATURE-----
Panda Security Response.asc
Description: Panda Security Response.asc
_______________________________________________ Full-Disclosure - We believe in it. Charter: http://lists.grok.org.uk/full-disclosure-charter.html Hosted and sponsored by Secunia - http://secunia.com/
| <Prev in Thread] | Current Thread | [Next in Thread> |
|---|---|---|
| ||
| Previous by Date: | [Full-disclosure] [ GLSA 200709-15 ] BEA JRockit: Multiple vulnerabilities, Raphael Marichez |
|---|---|
| Next by Date: | [Full-disclosure] COSEINC Linux Advisory #2: IA32 System Call Emulation Vulnerability, Wojciech Purczynski |
| Previous by Thread: | Re: [Full-disclosure] Panda Antivirus 2008 Local Privileg Escalation (UPS they did it again), 3APA3A |
| Next by Thread: | [Full-disclosure] [ GLSA 200709-12 ] Poppler: Two buffer overflow vulnerabilities, Raphael Marichez |
| Indexes: | [Date] [Thread] [Top] [All Lists] |