CVE-2008-2363

Severity CVSS v4.0:
Pending analysis
Type:
CWE-119 Buffer Errors
Publication date:
02/06/2008
Last modified:
09/04/2025

Description

The PartsBatch class in Pan 0.132 and earlier does not properly manage the data structures for Parts batches, which allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a crafted .nzb file that triggers a heap-based buffer overflow.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:pan:pan:*:*:*:*:*:*:*:* 0.132 (including)
cpe:2.3:a:pan:pan:0.105:*:*:*:*:*:*:*
cpe:2.3:a:pan:pan:0.106:*:*:*:*:*:*:*
cpe:2.3:a:pan:pan:0.107:*:*:*:*:*:*:*
cpe:2.3:a:pan:pan:0.108:*:*:*:*:*:*:*
cpe:2.3:a:pan:pan:0.109:*:*:*:*:*:*:*
cpe:2.3:a:pan:pan:0.110:*:*:*:*:*:*:*
cpe:2.3:a:pan:pan:0.111:*:*:*:*:*:*:*
cpe:2.3:a:pan:pan:0.112:*:*:*:*:*:*:*
cpe:2.3:a:pan:pan:0.113:*:*:*:*:*:*:*
cpe:2.3:a:pan:pan:0.114:*:*:*:*:*:*:*
cpe:2.3:a:pan:pan:0.115:*:*:*:*:*:*:*
cpe:2.3:a:pan:pan:0.116:*:*:*:*:*:*:*
cpe:2.3:a:pan:pan:0.117:*:*:*:*:*:*:*
cpe:2.3:a:pan:pan:0.118:*:*:*:*:*:*:*