CVE-2008-2363

UnknownEPSS 5.85%

Last modified

CVE-2008-2363 is a vulnerability of currently unknown severity. The PartsBatch class in Pan 0.132 and earlier does not properly manage the data structures for Parts batches, which allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a crafted .nzb file that triggers a heap-based buffer overflow.. EPSS estimates a 5.85% chance of exploitation in the next 30 days.

Description

The PartsBatch class in Pan 0.132 and earlier does not properly manage the data structures for Parts batches, which allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a crafted .nzb file that triggers a heap-based buffer overflow.

Metrics

EPSS Probability
5.85%

92.3th percentile

Probability of exploitation in the next 30 days. Learn more

Weakness Enumeration

Affected Software

VendorProductVersions
PanPan<= 0.132
PanPan0.105
PanPan0.106
PanPan0.107
PanPan0.108
PanPan0.109
PanPan0.110
PanPan0.111
PanPan0.112
PanPan0.113
PanPan0.114
PanPan0.115
PanPan0.116
PanPan0.117
PanPan0.118
PanPan0.119
PanPan0.120
PanPan0.121
PanPan0.122
PanPan0.123
PanPan0.124
PanPan0.125
PanPan0.126
PanPan0.127
PanPan0.128
PanPan0.129
PanPan0.130
PanPan0.131

References

Timeline

Published
Last Modified
Status
Modified

Frequently Asked Questions

What is CVE-2008-2363?
The PartsBatch class in Pan 0.132 and earlier does not properly manage the data structures for Parts batches, which allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a crafted .nzb file that triggers a heap-based buffer overflow.
How severe is CVE-2008-2363?
Severity scoring for CVE-2008-2363 is pending analysis. The EPSS model estimates a 5.85% probability of exploitation in the next 30 days.
How do I fix CVE-2008-2363?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

Are you affected by CVE-2008-2363?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST