PT-2004-3665 · Neon · Libneon

Stefan Esser

·

Publicado

1970-01-01

·

Atualizado

2020-10-09

·

CVE-2004-0398

CVSS v2.0

7.5

Alta

VetorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions libneon versions 0.24.5 and earlier
Description The issue is related to a heap-based buffer overflow in the ne rfc1036 parse date parsing function of the neon library. This allows remote WebDAV servers to execute arbitrary code on the client. Multiple vulnerabilities in the libneon package can lead to disruption of confidentiality, integrity, and availability of protected information. These vulnerabilities can be exploited remotely.
Recommendations For libneon versions 0.24.5 and earlier, update to a version later than 0.24.5 to resolve the issue. As a temporary workaround, consider restricting access to the ne rfc1036 parse function until a patch is available.

Correção

Memory Corruption

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2015-01965
BDU:2015-01966
CVE-2004-0398
DSA-506
DSA-507

Produtos afetados

Libneon