PT-2004-3665 · Neon · Libneon
Stefan Esser
·
Published
1970-01-01
·
Updated
2020-10-09
·
CVE-2004-0398
CVSS v2.0
7.5
High
| Vector | AV:N/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
libneon versions 0.24.5 and earlier
Description
The issue is related to a heap-based buffer overflow in the ne rfc1036 parse date parsing function of the neon library. This allows remote WebDAV servers to execute arbitrary code on the client. Multiple vulnerabilities in the libneon package can lead to disruption of confidentiality, integrity, and availability of protected information. These vulnerabilities can be exploited remotely.
Recommendations
For libneon versions 0.24.5 and earlier, update to a version later than 0.24.5 to resolve the issue.
As a temporary workaround, consider restricting access to the ne rfc1036 parse function until a patch is available.
Fix
Memory Corruption
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Libneon