Nom du paquet
pan
Date
2008-09-22
Advisory ID
MDVSA-2008:201
Affected versions
2008.1 i586 , 2008.1 x86_64 , 2008.0 i586 , 2008.0 x86_64

Problem description

Pavel Polischouk found a boundary error in the PartsBatch class in the
Pan newsreader when processing .nzb files, which could allow remote
attackers to cause a denial of serice (application crash) or possibly
execute arbitrary code via a crafted .nzb file (CVE-2008-2363).

The updated packages have been patched to prevent this issue.

Updated packages

2008.1 i586

 85af89fdd8fd639cbbeea702e10b4dfd  2008.1/i586/pan-0.132-3.1mdv2008.1.i586.rpm 
 78a5042fe39589632d1ac90a90a43862  2008.1/SRPMS/pan-0.132-3.1mdv2008.1.src.rpm

2008.1 x86_64

 35e28bf1628881af32a4c66c83041c6b  2008.1/x86_64/pan-0.132-3.1mdv2008.1.x86_64.rpm 
 78a5042fe39589632d1ac90a90a43862  2008.1/SRPMS/pan-0.132-3.1mdv2008.1.src.rpm

2008.0 i586

 1efb1805b839ee9de0ccdf583eaa96eb  2008.0/i586/pan-0.132-2.1mdv2008.0.i586.rpm 
 a9a8a84906e9943ca42d82e0a76d6af9  2008.0/SRPMS/pan-0.132-2.1mdv2008.0.src.rpm

2008.0 x86_64

 ecef9d793ceded193f1cf5800afa2357  2008.0/x86_64/pan-0.132-2.1mdv2008.0.x86_64.rpm 
 a9a8a84906e9943ca42d82e0a76d6af9  2008.0/SRPMS/pan-0.132-2.1mdv2008.0.src.rpm

References