Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 162318 - net-misc/neon: a denial of service (crash) via a URI with non-ASCII characters (CVE-2007-0157)
Summary: net-misc/neon: a denial of service (crash) via a URI with non-ASCII character...
Status: RESOLVED FIXED
Alias: None
Product: Gentoo Linux
Classification: Unclassified
Component: Current packages (show other bugs)
Hardware: All Linux
: High normal (vote)
Assignee: Paul de Vrieze (RETIRED)
URL: http://nvd.nist.gov/nvd.cfm?cvename=C...
Whiteboard:
Keywords:
Depends on:
Blocks:
 
Reported: 2007-01-16 04:13 UTC by Kalin KOZHUHAROV
Modified: 2007-11-10 19:40 UTC (History)
0 users

See Also:
Package list:
Runtime testing required: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Kalin KOZHUHAROV 2007-01-16 04:13:39 UTC
Please see the URL.

Reproducible: Didn't try

Steps to Reproduce:




Patch available here:

http://bugs.debian.org/cgi-bin/bugreport.cgi/neon26_0.26.2-3_to_mdx1.diff?bug=404723;msg=5;att=2

Is this upstream?
Do we need GLSA for that?
Comment 1 Raphael Marichez (Falco) (RETIRED) gentoo-dev 2007-01-17 22:46:54 UTC
it's a client-side DoS, usually we don't handle client-side DoS since a bad URI is also a form of disruption of service.

But thanks a lot for the report, Kalin. Reassigning to the maintainer as a non-security bug.
Comment 2 Raphael Marichez (Falco) (RETIRED) gentoo-dev 2007-01-17 22:52:03 UTC
And reassiging. Paul is not the real maintainer, but... who else?

There is no upstream fixed release according to http://www.webdav.org/neon/

A proposed patch is provided in the debian bug
http://bugs.debian.org/cgi-bin/bugreport.cgi/neon26_0.26.2-3_to_mdx1.diff?bug=404723;msg=5;att=2

Paul, act as you want :)
Comment 3 Carsten Lohrke (RETIRED) gentoo-dev 2007-05-14 13:47:48 UTC
bumped to 0.26.3 at least
Comment 4 Benedikt Böhm (RETIRED) gentoo-dev 2007-11-10 19:40:04 UTC
fixed in 0.26.4