Openwall GNU/*/Linux - a small security-enhanced Linux distro for servers
[<prev] [next>] [day] [month] [year] [list]
Date: Thu, 29 May 2008 10:17:10 -0400
From: Pavel Polischouk <pavel.polischouk@...il.com>
To: oss-security@...ts.openwall.com
Subject: CVE-2008-2363: pan - heap overflow

Hi,

I discovered a heap overflow in pan affecting the parsing of .nzb files. 
Details (including stack dumps and offending .nzb files) in RedHat 
Bugzilla entry:

https://bugzilla.redhat.com/show_bug.cgi?id=446902

Patch: https://bugzilla.redhat.com/attachment.cgi?id=306880

Links to this bug at other project/vendor sites:

GNOME bugzilla: http://bugzilla.gnome.org/show_bug.cgi?id=535413
Gentoo bugzilla: http://bugs.gentoo.org/show_bug.cgi?id=224051

Project developers have been notified. CVE issued by Red Hat Security 
Response Team.

Thanks,
Pavel

Powered by blists - more mailing lists

Please check out the Open Source Software Security Wiki, which is counterpart to this mailing list.

Powered by Openwall GNU/*/Linux - Powered by OpenVZ