CVE-2008-2363

The PartsBatch class in Pan 0.132 and earlier does not properly manage the data structures for Parts batches, which allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a crafted .nzb file that triggers a heap-based buffer overflow.
Configurations

Configuration 1

cpe:2.3:a:pan:pan:0.109:*:*:*:*:*:*:*
cpe:2.3:a:pan:pan:0.124:*:*:*:*:*:*:*
cpe:2.3:a:pan:pan:0.106:*:*:*:*:*:*:*
cpe:2.3:a:pan:pan:0.113:*:*:*:*:*:*:*
cpe:2.3:a:pan:pan:0.116:*:*:*:*:*:*:*
cpe:2.3:a:pan:pan:0.131:*:*:*:*:*:*:*
cpe:2.3:a:pan:pan:0.107:*:*:*:*:*:*:*
cpe:2.3:a:pan:pan:0.122:*:*:*:*:*:*:*
cpe:2.3:a:pan:pan:0.125:*:*:*:*:*:*:*
cpe:2.3:a:pan:pan:0.114:*:*:*:*:*:*:*
cpe:2.3:a:pan:pan:0.127:*:*:*:*:*:*:*
cpe:2.3:a:pan:pan:0.121:*:*:*:*:*:*:*
cpe:2.3:a:pan:pan:0.117:*:*:*:*:*:*:*
cpe:2.3:a:pan:pan:*:*:*:*:*:*:*:*
cpe:2.3:a:pan:pan:0.111:*:*:*:*:*:*:*
cpe:2.3:a:pan:pan:0.110:*:*:*:*:*:*:*
cpe:2.3:a:pan:pan:0.119:*:*:*:*:*:*:*
cpe:2.3:a:pan:pan:0.120:*:*:*:*:*:*:*
cpe:2.3:a:pan:pan:0.126:*:*:*:*:*:*:*
cpe:2.3:a:pan:pan:0.108:*:*:*:*:*:*:*
cpe:2.3:a:pan:pan:0.115:*:*:*:*:*:*:*
cpe:2.3:a:pan:pan:0.118:*:*:*:*:*:*:*
cpe:2.3:a:pan:pan:0.123:*:*:*:*:*:*:*
cpe:2.3:a:pan:pan:0.112:*:*:*:*:*:*:*
cpe:2.3:a:pan:pan:0.130:*:*:*:*:*:*:*
cpe:2.3:a:pan:pan:0.128:*:*:*:*:*:*:*
cpe:2.3:a:pan:pan:0.105:*:*:*:*:*:*:*
cpe:2.3:a:pan:pan:0.129:*:*:*:*:*:*:*

Information

Published : 2008-06-02 09:30

Updated : 2017-08-08 01:30


NVD link : CVE-2008-2363

Mitre link : CVE-2008-2363

Products Affected
No products.
CWE
CWE-119

Improper Restriction of Operations within the Bounds of a Memory Buffer