oss-sec mailing list archives

CVE-2008-2363: pan - heap overflow


From: Pavel Polischouk <pavel.polischouk () gmail com>
Date: Thu, 29 May 2008 10:17:10 -0400

Hi,

I discovered a heap overflow in pan affecting the parsing of .nzb files. Details (including stack dumps and offending .nzb files) in RedHat Bugzilla entry:

https://bugzilla.redhat.com/show_bug.cgi?id=446902

Patch: https://bugzilla.redhat.com/attachment.cgi?id=306880

Links to this bug at other project/vendor sites:

GNOME bugzilla: http://bugzilla.gnome.org/show_bug.cgi?id=535413
Gentoo bugzilla: http://bugs.gentoo.org/show_bug.cgi?id=224051

Project developers have been notified. CVE issued by Red Hat Security Response Team.

Thanks,
Pavel


Current thread: