Pan '.nzb' File Parsing Heap Overflow Vulnerability
BID:29421
Info
Pan '.nzb' File Parsing Heap Overflow Vulnerability
| Bugtraq ID: | 29421 |
| Class: | Boundary Condition Error |
| CVE: |
CVE-2008-2363 |
| Remote: | Yes |
| Local: | No |
| Published: | May 29 2008 12:00AM |
| Updated: | Apr 13 2015 09:33PM |
| Credit: | Pavel Polischouk |
| Vulnerable: |
Ubuntu Ubuntu Linux 8.04 LTS sparc Ubuntu Ubuntu Linux 8.04 LTS powerpc Ubuntu Ubuntu Linux 8.04 LTS lpia Ubuntu Ubuntu Linux 8.04 LTS i386 Ubuntu Ubuntu Linux 8.04 LTS amd64 Slackware Linux 12.1 Slackware Linux 12.0 Slackware Linux -current S.u.S.E. openSUSE 10.3 Pan Pan 0.132 Pan Pan 0.131 Pan Pan 0.130 Pan Pan 0.129 Pan Pan 0.128 Mandriva Linux Mandrake 2008.1 x86_64 Mandriva Linux Mandrake 2008.1 Mandriva Linux Mandrake 2008.0 x86_64 Mandriva Linux Mandrake 2008.0 Gentoo Linux |
| Not Vulnerable: | |
Discussion
Pan '.nzb' File Parsing Heap Overflow Vulnerability
Pan is prone to a heap-based buffer-overflow vulnerability because it fails to properly bounds-check user-supplied input. The vulnerability occurs when handling malformed '.nzb' files.
Successfully exploiting this issue allows attackers to execute arbitrary code with the privileges of a user running the application. Failed exploit attempts will result in a denial-of-service condition.
Pan is prone to a heap-based buffer-overflow vulnerability because it fails to properly bounds-check user-supplied input. The vulnerability occurs when handling malformed '.nzb' files.
Successfully exploiting this issue allows attackers to execute arbitrary code with the privileges of a user running the application. Failed exploit attempts will result in a denial-of-service condition.
Exploit / POC
Pan '.nzb' File Parsing Heap Overflow Vulnerability
Currently we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Currently we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution / Fix
Pan '.nzb' File Parsing Heap Overflow Vulnerability
Solution:
Updates are available. Please see the references for more information.
Mandriva Linux Mandrake 2008.1 x86_64
Mandriva Linux Mandrake 2008.1
Ubuntu Ubuntu Linux 8.04 LTS powerpc
Ubuntu Ubuntu Linux 8.04 LTS sparc
Pan Pan 0.129
Ubuntu Ubuntu Linux 8.04 LTS i386
Pan Pan 0.132
Mandriva Linux Mandrake 2008.0 x86_64
Ubuntu Ubuntu Linux 8.04 LTS amd64
Pan Pan 0.131
Mandriva Linux Mandrake 2008.0
Pan Pan 0.130
Pan Pan 0.128
Ubuntu Ubuntu Linux 8.04 LTS lpia
Solution:
Updates are available. Please see the references for more information.
Mandriva Linux Mandrake 2008.1 x86_64
-
Mandriva pan-0.132-3.1mdv2008.1.x86_64.rpm
http://www.mandriva.com/en/download/
Mandriva Linux Mandrake 2008.1
-
Mandriva pan-0.132-3.1mdv2008.1.i586.rpm
http://www.mandriva.com/en/download/
Ubuntu Ubuntu Linux 8.04 LTS powerpc
-
Ubuntu pan_0.132-2ubuntu2.1_powerpc.deb
http://ports.ubuntu.com/pool/main/p/pan/pan_0.132-2ubuntu2.1_powerpc.d eb
Ubuntu Ubuntu Linux 8.04 LTS sparc
-
Ubuntu pan_0.132-2ubuntu2.1_sparc.deb
http://ports.ubuntu.com/pool/main/p/pan/pan_0.132-2ubuntu2.1_sparc.deb
Pan Pan 0.129
-
Pan pan-0.132.sortfix.patch
https://bugzilla.redhat.com/attachment.cgi?id=306880
Ubuntu Ubuntu Linux 8.04 LTS i386
-
Ubuntu pan_0.132-2ubuntu2.1_i386.deb
http://security.ubuntu.com/ubuntu/pool/main/p/pan/pan_0.132-2ubuntu2.1 _i386.deb
Pan Pan 0.132
-
Pan pan-0.132.sortfix.patch
https://bugzilla.redhat.com/attachment.cgi?id=306880
Mandriva Linux Mandrake 2008.0 x86_64
-
Mandriva pan-0.132-2.1mdv2008.0.x86_64.rpm
http://www.mandriva.com/en/download/
Ubuntu Ubuntu Linux 8.04 LTS amd64
-
Ubuntu pan_0.132-2ubuntu2.1_amd64.deb
http://security.ubuntu.com/ubuntu/pool/main/p/pan/pan_0.132-2ubuntu2.1 _amd64.deb
Pan Pan 0.131
-
Pan pan-0.132.sortfix.patch
https://bugzilla.redhat.com/attachment.cgi?id=306880
Mandriva Linux Mandrake 2008.0
-
Mandriva pan-0.132-2.1mdv2008.0.i586.rpm
http://www.mandriva.com/en/download/
Pan Pan 0.130
-
Pan pan-0.132.sortfix.patch
https://bugzilla.redhat.com/attachment.cgi?id=306880
Pan Pan 0.128
-
Pan pan-0.132.sortfix.patch
https://bugzilla.redhat.com/attachment.cgi?id=306880
Ubuntu Ubuntu Linux 8.04 LTS lpia
-
Ubuntu pan_0.132-2ubuntu2.1_lpia.deb
http://ports.ubuntu.com/pool/main/p/pan/pan_0.132-2ubuntu2.1_lpia.deb
References
Pan '.nzb' File Parsing Heap Overflow Vulnerability
References:
References:
- Bug 535413 �?? [Security] CVE-2008-2363 Buffer overflow in pan when parsing *.nzb (Duncan)
- Bugzilla Bug 446902: CVE-2008-2363 Assertion fails when starting PAN (Pavel Polischouk)
- CVE-2008-2363: pan - heap overflow (Pavel Polischouk )
- Gentoo Bugzilla Bug 224051 (Gentoo )
- Pan Homepage (Pan)