Pan Newsreader Can Be Crashed By Remote Users
|
|
SecurityTracker Alert ID: 1008285
|
|
CVE Reference: CAN-2003-0855
(Links to External Site)
|
Date: Nov 24 2003
|
Impact: Denial of service via network
|
Fix Available: Yes
Vendor Confirmed: Yes
|
Version(s): 0.13.3.93 and prior
|
Description: A vulnerability was reported in the Pan newsreader. A remote user can cause the client to crash.
It is reported that a remote user can post a message containing certain headers to cause a target user's Pan reader to crash when loading the message.
|
Impact: A remote user can post a news message that will cause a target user's client to crash.
|
Solution: The vendor has released a fixed version (0.13.4), available at:
http://pan.rebelbase.com/download/
|
Vendor URL: pan.rebelbase.com/ (Links to External Site)
|
Cause: Exception handling error
|
Underlying OS: Linux (Any), UNIX (Any)
|
|
Message History:
This archive entry has one or more follow-up message(s) listed below.
|
Source Message Contents
|
Date: Mon, 24 Nov 2003 10:12:48 -0500
Subject: bugzilla.gnome.org/show_bug.cgi?id=107025
|
bugzilla.gnome.org/show_bug.cgi?id=107025
A denial of service vulnerability was reported in Pan version 0.13.3.93 and prior
versions. Certain headers can cause Pan to crash.
CVE: CAN-2003-0855
|
|