9.3

CVE-2008-2363

The PartsBatch class in Pan 0.132 and earlier does not properly manage the data structures for Parts batches, which allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a crafted .nzb file that triggers a heap-based buffer overflow.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Pan ≫ Pan Version <= 0.132
Pan ≫ Pan Version 0.105
Pan ≫ Pan Version 0.106
Pan ≫ Pan Version 0.107
Pan ≫ Pan Version 0.108
Pan ≫ Pan Version 0.109
Pan ≫ Pan Version 0.110
Pan ≫ Pan Version 0.111
Pan ≫ Pan Version 0.112
Pan ≫ Pan Version 0.113
Pan ≫ Pan Version 0.114
Pan ≫ Pan Version 0.115
Pan ≫ Pan Version 0.116
Pan ≫ Pan Version 0.117
Pan ≫ Pan Version 0.118
Pan ≫ Pan Version 0.119
Pan ≫ Pan Version 0.120
Pan ≫ Pan Version 0.121
Pan ≫ Pan Version 0.122
Pan ≫ Pan Version 0.123
Pan ≫ Pan Version 0.124
Pan ≫ Pan Version 0.125
Pan ≫ Pan Version 0.126
Pan ≫ Pan Version 0.127
Pan ≫ Pan Version 0.128
Pan ≫ Pan Version 0.129
Pan ≫ Pan Version 0.130
Pan ≫ Pan Version 0.131
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 5.85% 0.922
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 9.3 8.6 10
AV:N/AC:M/Au:N/C:C/I:C/A:C
CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer

The product performs operations on a memory buffer, but it reads from or writes to a memory location outside the buffer's intended boundary. This may result in read or write operations on unexpected memory locations that could be linked to other variables, data structures, or internal program data.

http://secunia.com/advisories/30717
Vendor Advisory
http://www.novell.com/linux/security/advisories/2008_13_sr.html
http://bugs.gentoo.org/show_bug.cgi?id=224051
Patch
http://bugzilla.gnome.org/show_bug.cgi?id=535413
Patch
http://marc.info/?l=oss-security&m=121207185600564&w=2
Patch
http://secunia.com/advisories/31315
Vendor Advisory
http://security.gentoo.org/glsa/glsa-200807-15.xml
http://www.mandriva.com/security/advisories?name=MDVSA-2008:201
http://www.securityfocus.com/bid/29421
Patch
https://bugzilla.redhat.com/show_bug.cgi?id=446902
https://exchange.xforce.ibmcloud.com/vulnerabilities/42750