PT-2008-1087 · Pan · Pan

Publicado

2008-06-02

·

Atualizado

2017-08-08

·

CVE-2008-2363

CVSS v2.0

9.3

Alta

VetorAV:N/AC:M/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Pan versions 0.132 and earlier
Description The issue is related to the PartsBatch class, which does not properly manage data structures for Parts batches. This allows remote attackers to cause a denial of service, potentially leading to an application crash, and possibly execute arbitrary code via a crafted .nzb file that triggers a heap-based buffer overflow. The vulnerability may also lead to a violation of confidentiality, integrity, and availability of protected information.
Recommendations For Pan versions 0.132 and earlier, as a temporary workaround, consider restricting the use of the PartsBatch class until a patch is available. Avoid using crafted .nzb files that may trigger a heap-based buffer overflow. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Buffer Overflow

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2015-09342
CVE-2008-2363
OPENSUSE-SU-2024:11147-1

Produtos afetados

Pan