Vulnerability   
Search   
    Search 324607 CVE descriptions
and 146377 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

Test ID:1.3.6.1.4.1.25623.1.0.52787
Category:Fedora Local Security Checks
Title:Fedora Legacy Security Advisory FLSA-2004:1552
Summary:NOSUMMARY
Description:Description:

The remote host is missing updates announced in
advisory FLSA-2004:1552.

An updated cadaver package that fixes a vulnerability in neon exploitable
by a malicious DAV server is now available.

cadaver is a command-line WebDAV client that uses inbuilt code from neon,
an HTTP and WebDAV client library.

Versions of the neon client library up to and including 0.24.4 have been
found to contain a number of format string bugs. An attacker could create
a malicious WebDAV server in such a way as to allow arbitrary code
execution on the client should a user connect to it using cadaver. The
Common Vulnerabilities and Exposures project (cve.mitre.org) has assigned
the name CVE-2004-0179 to this issue. This issue was addressed in a previous
update for Red Hat Linux 9.

Stefan Esser discovered a flaw in the neon library which allows a heap
buffer overflow in a date parsing routine. An attacker could create
a malicious WebDAV server in such a way as to allow arbitrary code
execution on the client should a user connect to it using cadaver. The
Common Vulnerabilities and Exposures project (cve.mitre.org) has assigned
the name CVE-2004-0398 to this issue.

Users of cadaver are advised to upgrade to this updated package, which
contains patches correcting these issues.

Affected platforms:
Redhat 7.3
Redhat 9

Solution:
https://secure1.securityspace.com/smysecure/catid.html?in=FLSA-2004:1552
http://security.e-matters.de/advisories/062004.html

Risk factor : High

CVSS Score:
7.5

Cross-Ref: Common Vulnerability Exposure (CVE) ID: CVE-2004-0179
BugTraq ID: 10136
http://www.securityfocus.com/bid/10136
Bugtraq: 20040416 [OpenPKG-SA-2004.016] OpenPKG Security Advisory (neon) (Google Search)
http://marc.info/?l=bugtraq&m=108213873203477&w=2
Bugtraq: 20040416 void.at - neon format string bugs (Google Search)
http://marc.info/?l=bugtraq&m=108214147022626&w=2
Debian Security Information: DSA-487 (Google Search)
http://www.debian.org/security/2004/dsa-487
https://bugzilla.fedora.us/show_bug.cgi?id=1552
http://security.gentoo.org/glsa/glsa-200405-01.xml
http://security.gentoo.org/glsa/glsa-200405-04.xml
http://www.mandriva.com/security/advisories?name=MDKSA-2004:032
http://www.osvdb.org/5365
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1065
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10913
http://www.redhat.com/support/errata/RHSA-2004-157.html
http://www.redhat.com/support/errata/RHSA-2004-158.html
http://www.redhat.com/support/errata/RHSA-2004-159.html
http://www.redhat.com/support/errata/RHSA-2004-160.html
http://secunia.com/advisories/11363
SGI Security Advisory: 20040404-01-U
ftp://patches.sgi.com/support/free/security/advisories/20040404-01-U.asc
SuSE Security Announcement: SuSE-SA:2004:008 (Google Search)
http://lists.suse.com/archive/suse-security-announce/2004-Apr/0003.html
SuSE Security Announcement: SuSE-SA:2004:009 (Google Search)
http://lists.suse.com/archive/suse-security-announce/2004-Apr/0002.html
Common Vulnerability Exposure (CVE) ID: CVE-2004-0398
BugTraq ID: 10385
http://www.securityfocus.com/bid/10385
Bugtraq: 20040519 Advisory 06/2004: libneon date parsing vulnerability (Google Search)
http://marc.info/?l=bugtraq&m=108498433632333&w=2
Bugtraq: 20040519 [OpenPKG-SA-2004.024] OpenPKG Security Advisory (neon) (Google Search)
http://marc.info/?l=bugtraq&m=108500057108022&w=2
Computer Incident Advisory Center Bulletin: O-148
http://www.ciac.org/ciac/bulletins/o-148.shtml
Conectiva Linux advisory: CLA-2004:841
http://distro.conectiva.com.br/atualizacoes/?id=a&anuncio=000841
Debian Security Information: DSA-506 (Google Search)
http://www.debian.org/security/2004/dsa-506
Debian Security Information: DSA-507 (Google Search)
http://www.debian.org/security/2004/dsa-507
http://archives.neohapsis.com/archives/fulldisclosure/2004-05/0982.html
http://security.gentoo.org/glsa/glsa-200405-13.xml
http://security.gentoo.org/glsa/glsa-200405-15.xml
http://www.mandriva.com/security/advisories?name=MDKSA-2004:049
http://www.osvdb.org/6302
http://www.redhat.com/support/errata/RHSA-2004-191.html
http://secunia.com/advisories/11638
http://secunia.com/advisories/11650
http://secunia.com/advisories/11673
XForce ISS Database: neon-library-nerfc1036parse-bo(16192)
https://exchange.xforce.ibmcloud.com/vulnerabilities/16192
CopyrightCopyright (c) 2005 E-Soft Inc. http://www.securityspace.com

This is only one of 146377 vulnerability tests in our test suite. Find out more about running a complete security audit.

To run a free test of this vulnerability against your system, register below.




© 1998-2025 E-Soft Inc. All rights reserved.