PT-2004-3665 · Neon · Libneon

Stefan Esser

·

Published

1970-01-01

·

Updated

2020-10-09

·

CVE-2004-0398

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions libneon versions 0.24.5 and earlier
Description The issue is related to a heap-based buffer overflow in the ne rfc1036 parse date parsing function of the neon library. This allows remote WebDAV servers to execute arbitrary code on the client. Multiple vulnerabilities in the libneon package can lead to disruption of confidentiality, integrity, and availability of protected information. These vulnerabilities can be exploited remotely.
Recommendations For libneon versions 0.24.5 and earlier, update to a version later than 0.24.5 to resolve the issue. As a temporary workaround, consider restricting access to the ne rfc1036 parse function until a patch is available.

Fix

Memory Corruption

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2015-01965
BDU:2015-01966
CVE-2004-0398
DSA-506
DSA-507

Affected Products

Libneon