PT-2007-2953 · Newsbin · Newsbin Pro

Marsu

·

Published

2007-03-21

·

Updated

2017-10-11

·

CVE-2007-1569

CVSS v2.0

10

High

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions NewsBin Pro version 4.32
Description The issue is a stack-based buffer overflow that can be triggered by a yEnc (yEncode) encoded article with a long filename. This can be exploited using a .nzb file, potentially allowing remote attackers to cause a denial of service or execute arbitrary code.
Recommendations For NewsBin Pro version 4.32, consider avoiding the use of yEnc encoded articles with long filenames until a patch is available. As a temporary workaround, restrict the handling of .nzb files to minimize the risk of exploitation.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2007-1569

Affected Products

Newsbin Pro