Fedora: 2,1: neon Heap overflow vulnerability
Summary
neon is an HTTP and WebDAV client library, with a C interface;
providing a high-level interface to HTTP and WebDAV methods along
with a low-level interface for HTTP request handling. neon
supports persistent connections, proxy servers, basic, digest and
Kerberos authentication, and has complete SSL support.
neon is an HTTP and WebDAV client library, with a C interface;
providing a high-level interface to HTTP and WebDAV methods along
with a low-level interface for HTTP request handling. neon
supports persistent connections, proxy servers, basic, digest and
Kerberos authentication, and has complete SSL support.
Update Information:
Stefan Esser discovered a flaw in the neon library which allows a heap
buffer overflow in a date parsing routine. An attacker could create a
malicious WebDAV server in such a way as to allow arbitrary code
execution on the client should a user connect to it using a neon-based
application which uses the date parsing routines, such as cadaver.
The Common Vulnerabilities and Exposures project (cve.mitre.org) has
assigned the name CAN-2004-0398 to this issue. This update includes
packages with a patch for this issue.
* Sun May 16 2004 Joe Orton <jorton@redhat.com> 0.24.5-2.2
- rebuild for FC2 update
* Sun May 16 2004 Joe Orton <jorton@redhat.com> 0.24.5-2.1
- add security fix for CVE CAN-2004-0398
This update can be downloaded from:
435cce4188891f20707b16615c893413 SRPMS/neon-0.24.5-2.2.src.rpm
6dece9ed94cbf68834f7d84b6868f4d9 i386/neon-0.24.5-2.2.i386.rpm
d307e0e58a179d12b1c40c840279d6c9 i386/neon-devel-0.24.5-2.2.i386.rpm
4d4b66a4a49c82ed57ce4c00a2b0cebc i386/debug/neon-debuginfo-0.24.5-2.2.i386.rpm
ab0fb62241d6373f83081580d144cfee x86_64/neon-0.24.5-2.2.x86_64.rpm
ba481e85f740f718c10fc9e8ccc60f9f x86_64/neon-devel-0.24.5-2.2.x86_64.rpm
fcab8e5e26dccd7f1f904b0d1379198f x86_64/debug/neon-debuginfo-0.24.5-2.2.x86_64.rpm
This update can also be installed with the Update Agent; you can
launch the Update Agent with the 'up2date' command.
-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-
Fedora Update Notification
FEDORA-2004-129
2004-05-19
Product : Fedora Core 1
Name : neon
Version : 0.24.5
Release : 2.1
Summary : An HTTP and WebDAV client library
Description :
neon is an HTTP and WebDAV client library, with a C interface;
providing a high-level interface to HTTP and WebDAV methods along
with a low-level interface for HTTP request handling. neon
supports persistent connections, proxy servers, basic, digest and
Kerberos authentication, and has complete SSL support.
Stefan Esser discovered a flaw in the neon library which allows a heap
buffer overflow in a date parsing routine. An attacker could create a
malicious WebDAV server in such a way as to allow arbitrary code
execution on the client should a user connect to it using a neon-based
application which uses the date parsing routines, such as cadaver.
The Common Vulnerabilities and Exposures project (cve.mitre.org) has
assigned the name CAN-2004-0398 to this issue. This update includes
packages with a patch for this issue.
* Sun May 16 2004 Joe Orton <jorton@redhat.com> 0.24.5-2.1
- add security fix for CVE CAN-2004-0398
This update can be downloaded from:
71f0ddffbe8b5171b2fa2d93e55f8e35 SRPMS/neon-0.24.5-2.1.src.rpm
c215af0bae2c90672573090fee1ec706 i386/neon-0.24.5-2.1.i386.rpm
89c59069a0b48258b8b5f8cc66be5bf7 i386/neon-devel-0.24.5-2.1.i386.rpm
f7d813c7a96814072b097f15692771e9 i386/debug/neon-debuginfo-0.24.5-2.1.i386.rpm
841d910930f3def3f0202570b8c984a6 x86_64/neon-0.24.5-2.1.x86_64.rpm
92cc5ffa0588fe59bdd976308ea52971 x86_64/neon-devel-0.24.5-2.1.x86_64.rpm
03c24e6f0cd267e655a40127696a71b6 x86_64/debug/neon-debuginfo-0.24.5-2.1.x86_64.rpm
This update can also be installed with the Update Agent; you can
launch the Update Agent with the 'up2date' command.
Change Log
References
Fedora Update Notification FEDORA-2004-130 2004-05-19 Product : Fedora Core 2 Name : neon Version : 0.24.5 Release : 2.2 Summary : An HTTP and WebDAV client library Description : neon is an HTTP and WebDAV client library, with a C interface; providing a high-level interface to HTTP and WebDAV methods along with a low-level interface for HTTP request handling. neon supports persistent connections, proxy servers, basic, digest and Kerberos authentication, and has complete SSL support.