Name | CVE-2008-2363 |
Description | The PartsBatch class in Pan 0.132 and earlier does not properly manage the data structures for Parts batches, which allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a crafted .nzb file that triggers a heap-based buffer overflow. |
Source | CVE (at NVD; CERT, LWN, oss-sec, fulldisc, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more) |
Debian Bugs | 483562 |
Vulnerable and fixed packages
The table below lists information on source packages.
Source Package | Release | Version | Status |
---|
pan (PTS) | jessie | 0.139-3 | fixed |
| stretch | 0.141-2 | fixed |
| buster | 0.145-1 | fixed |
| bullseye | 0.146-2 | fixed |
| bookworm | 0.154-1 | fixed |
| sid, trixie | 0.161-1 | fixed |
The information below is based on the following data on fixed versions.
Package | Type | Release | Fixed Version | Urgency | Origin | Debian Bugs |
---|
pan | source | etch | (not affected) | | | |
pan | source | (unstable) | 0.132-3.1 | | | 483562 |
Notes
[etch] - pan <not-affected> (Vulnerable code not added until 0.130)
see http://svn.gnome.org/viewvc/pan2/trunk/pan/data/parts.cc?view=log&pathrev=286