PT-2004-1083 · Apache · Openoffice+1
Thomas Wana
·
Published
2004-04-15
·
Updated
2020-10-13
·
CVE-2004-0179
CVSS v2.0
6.8
Medium
| Vector | AV:N/AC:M/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
neon versions 0.24.4 and earlier
Cadaver (affected versions not specified)
Subversion versions 0.27.0 and earlier
OpenOffice (affected versions not specified)
Description
The issue allows remote malicious WebDAV servers to execute arbitrary code due to multiple format string vulnerabilities. This can lead to a violation of confidentiality, integrity, and availability of protected information. The vulnerability can be exploited remotely.
Recommendations
For neon versions 0.24.4 and earlier, update to a version later than 0.24.4.
For Cadaver, Subversion, and OpenOffice, at the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
Use of Externally-Controlled Format String
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Openoffice
Subversion