USN-845-1: Pan vulnerability

view full story

http://www.ubuntu.com – Referenced CVEs:  CVE-2008-2363 Description:  =========================================================== Ubuntu Security Notice USN-845-1 October 08, 2009 pan vulnerability CVE-2008-2363 =========================================================== A security issue affects the following Ubuntu releases: Ubuntu 8.04 LTS This advisory also applies to the corresponding versions of Kubuntu, Edubuntu, and Xubuntu. The problem can be corrected by upgrading your system to the following package versions: Ubuntu 8.04 LTS: pan 0.132-2ubuntu2.1 In general, a standard system upgrade is sufficient to effect the necessary changes. Details follow: Pavel Polischouk discovered that Pan incorrectly handled certain data structures. If a user were tricked into viewing malicious nntp data, a remote attacker could cause a denial of service or possibly execute arbitrary code with the privileges of the user invoking the program. (Distributions)