Heap-based buffer overflow in the ne_rfc1036_parse date parsing function for the neon library (libneon) 0.24.5 and earlier, as used by cadaver before 0.22, allows remote WebDAV servers to execute arbitrary code on the client.
References
Configurations
History
20 Nov 2024, 23:48
Type | Values Removed | Values Added |
---|---|---|
References | () http://archives.neohapsis.com/archives/fulldisclosure/2004-05/0982.html - Broken Link | |
References | () http://distro.conectiva.com.br/atualizacoes/?id=a&anuncio=000841 - Broken Link | |
References | () http://marc.info/?l=bugtraq&m=108498433632333&w=2 - Third Party Advisory | |
References | () http://marc.info/?l=bugtraq&m=108500057108022&w=2 - Third Party Advisory | |
References | () http://secunia.com/advisories/11638 - Third Party Advisory | |
References | () http://secunia.com/advisories/11650 - Third Party Advisory | |
References | () http://secunia.com/advisories/11673 - Third Party Advisory | |
References | () http://security.gentoo.org/glsa/glsa-200405-13.xml - Third Party Advisory | |
References | () http://security.gentoo.org/glsa/glsa-200405-15.xml - Third Party Advisory | |
References | () http://www.ciac.org/ciac/bulletins/o-148.shtml - Broken Link | |
References | () http://www.debian.org/security/2004/dsa-506 - Third Party Advisory | |
References | () http://www.debian.org/security/2004/dsa-507 - Third Party Advisory | |
References | () http://www.mandriva.com/security/advisories?name=MDKSA-2004:049 - Third Party Advisory | |
References | () http://www.osvdb.org/6302 - Broken Link | |
References | () http://www.redhat.com/support/errata/RHSA-2004-191.html - Third Party Advisory | |
References | () http://www.securityfocus.com/bid/10385 - Third Party Advisory, VDB Entry | |
References | () https://bugzilla.fedora.us/show_bug.cgi?id=1552 - Broken Link | |
References | () https://exchange.xforce.ibmcloud.com/vulnerabilities/16192 - Third Party Advisory, VDB Entry |
Information
Published : 2004-07-07 04:00
Updated : 2024-11-20 23:48
NVD link : CVE-2004-0398
Mitre link : CVE-2004-0398
CVE.ORG link : CVE-2004-0398
JSON object : View
Products Affected
debian
- debian_linux
webdav
- neon
- cadaver
CWE
CWE-787
Out-of-bounds Write