Novell Home

CVE-2008-2363

Common Vulnerabilities and Exposures

[Previous] [Index] [Next]

Upstream information

CVE-2008-2363 at MITRE

Description

The PartsBatch class in Pan 0.132 and earlier does not properly manage the data structures for Parts batches, which allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a crafted .nzb file that triggers a heap-based buffer overflow.

NVD CVSS v2 Base Score: 9.3 (AV:N/AC:M/Au:N/C:C/I:C/A:C)

Novell/SUSE information

Novell Bugzilla entry: 395452, 395469

SUSE Security Advisories:

List of released packages

Product(s) Fixed package version(s) References
openSUSE 10.3
  • pan >= 0.132-33.2

© 2012 Novell