Login
Newsletter
Werbung

Sicherheit: Pufferüberlauf in neon (Fedora Core 2)
Aktuelle Meldungen Distributionen
Name: Pufferüberlauf in neon (Fedora Core 2)
ID: FEDORA-2004-130
Distribution: Fedora
Plattformen: Fedora Core 2
Datum: Do, 20. Mai 2004, 13:00
Referenzen: http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0398
Applikationen: neon

Originalnachricht

---------------------------------------------------------------------
Fedora Update Notification
FEDORA-2004-130
2004-05-19
---------------------------------------------------------------------

Product : Fedora Core 2
Name : neon
Version : 0.24.5
Release : 2.2
Summary : An HTTP and WebDAV client library
Description :
neon is an HTTP and WebDAV client library, with a C interface;
providing a high-level interface to HTTP and WebDAV methods along
with a low-level interface for HTTP request handling. neon
supports persistent connections, proxy servers, basic, digest and
Kerberos authentication, and has complete SSL support.

---------------------------------------------------------------------
Update Information:

Stefan Esser discovered a flaw in the neon library which allows a heap
buffer overflow in a date parsing routine. An attacker could create a
malicious WebDAV server in such a way as to allow arbitrary code
execution on the client should a user connect to it using a neon-based
application which uses the date parsing routines, such as cadaver.

The Common Vulnerabilities and Exposures project (cve.mitre.org) has
assigned the name CAN-2004-0398 to this issue. This update includes
packages with a patch for this issue.

---------------------------------------------------------------------
* Sun May 16 2004 Joe Orton <jorton@redhat.com> 0.24.5-2.2

- rebuild for FC2 update

* Sun May 16 2004 Joe Orton <jorton@redhat.com> 0.24.5-2.1

- add security fix for CVE CAN-2004-0398

---------------------------------------------------------------------
This update can be downloaded from:
http://download.fedora.redhat.com/pub/fedora/linux/core/updates/2/

435cce4188891f20707b16615c893413 SRPMS/neon-0.24.5-2.2.src.rpm
6dece9ed94cbf68834f7d84b6868f4d9 i386/neon-0.24.5-2.2.i386.rpm
d307e0e58a179d12b1c40c840279d6c9 i386/neon-devel-0.24.5-2.2.i386.rpm
4d4b66a4a49c82ed57ce4c00a2b0cebc i386/debug/neon-debuginfo-0.24.5-2.2.i386.rpm
ab0fb62241d6373f83081580d144cfee x86_64/neon-0.24.5-2.2.x86_64.rpm
ba481e85f740f718c10fc9e8ccc60f9f x86_64/neon-devel-0.24.5-2.2.x86_64.rpm
fcab8e5e26dccd7f1f904b0d1379198f
x86_64/debug/neon-debuginfo-0.24.5-2.2.x86_64.rpm

This update can also be installed with the Update Agent; you can
launch the Update Agent with the 'up2date' command.
---------------------------------------------------------------------


--
fedora-announce-list mailing list
fedora-announce-list@redhat.com
http://www.redhat.com/mailman/listinfo/fedora-announce-list
Pro-Linux
Pro-Linux @Facebook
Neue Nachrichten
Werbung