Pavel Polischouk | 29 May 16:13

CVE-2008-2363: pan - heap overflow

Hi,

I discovered a heap overflow in pan affecting the parsing of .nzb files. 
Details (including stack dumps and offending .nzb files) in RedHat 
Bugzilla entry:

https://bugzilla.redhat.com/show_bug.cgi?id=446902

Patch: https://bugzilla.redhat.com/attachment.cgi?id=306880

Links to this bug at other project/vendor sites:

GNOME bugzilla: http://bugzilla.gnome.org/show_bug.cgi?id=535413
Gentoo bugzilla: http://bugs.gentoo.org/show_bug.cgi?id=224051

Project developers have been notified. CVE issued by Red Hat Security 
Response Team.

Thanks,
Pavel


Gmane