CVE-2008-2363
Published: 2 June 2008
The PartsBatch class in Pan 0.132 and earlier does not properly manage the data structures for Parts batches, which allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a crafted .nzb file that triggers a heap-based buffer overflow.
Notes
Author | Note |
---|---|
kees | http://svn.gnome.org/viewvc/pan2/trunk/pan/data/parts.cc?view=log&pathrev=286 |
Priority
Status
Package | Release | Status |
---|---|---|
pan Launchpad, Ubuntu, Debian |
dapper |
Ignored
(end of life)
|
feisty |
Ignored
(end of life, was needed)
|
|
gutsy |
Ignored
(end of life, was needed)
|
|
hardy |
Released
(0.132-2ubuntu2.1)
|
|
intrepid |
Not vulnerable
(0.132-3.1)
|
|
jaunty |
Not vulnerable
(0.132-3.1)
|
|
upstream |
Released
(0.132-3.1)
|
|
Patches: vendor: http://patch-tracker.debian.org/patch/series/dl/pan/0.132-3.1/CVE-2008-2363.dpatch |