PT-2008-5105 · Neon · Neon

Joe Orton

·

Publicado

2008-08-27

·

Atualizado

2024-06-15

·

CVE-2008-3746

CVSS v2.0

4.3

Média

VetorAV:N/AC:M/Au:N/C:N/I:N/A:P
Name of the Vulnerable Software and Affected Versions neon versions 0.28.0 through 0.28.2
Description The issue allows remote servers to cause a denial of service, resulting in a NULL pointer dereference and crash. This is related to Digest authentication, specifically the Digest domain parameter support, and the parse domain function.
Recommendations For versions 0.28.0 through 0.28.2, consider disabling Digest authentication as a temporary workaround until a patch is available. Restrict access to the parse domain function to minimize the risk of exploitation.

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2008-3746
OPENSUSE-SU-2024:11080-1

Produtos afetados

Neon