Red Hat Bugzilla – Bug 107519
CAN-2003-0855 Pan crash on long email address
Last modified: 2007-03-27 00:10:57 EDT
Description of problem:
If you try to view a group with a posting with a long sender address pan core dumps.
Version-Release number of selected component (if applicable):
Happens every time.
Steps to Reproduce:
1. Post a message with a long address in From:
2. Try to view the group with pan
Pan dumps core
Pan views the group correctly possibly truncating the email address to a
The bug is listed as security because it is possibly a buffer overflow that
could potentially be used to execute arbitrary code in every pan client viewing
The problem was first seen with a 702 character long email address in the
the group dk.test on the server news.tele.dk.
Pan also dumps core while getting the list of newsgroups if the server does not
send a ^M char at the end of each line.
Okay, this is a known issue with patch available:
We'll look at doing a security update to PAN.
To follow up on this, the crash causes a null byte to be written to 0x00 which
causes a crash but isn't able to be exploited further (therefore this is limited
to a DoS). Errata in progress.
RHSA-2003:311 in progress
For the record, apparently this was fixed in 0.13.4.
An errata has been issued which should help the problem described in this bug report.
This report is therefore being closed with a resolution of ERRATA. For more information
on the solution and/or where to find the updated files, please follow the link below. You may reopen
this bug report if the solution does not work for you.