Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 47799 - net-misc/cadaver : package fixes security vulnerability in neon
Summary: net-misc/cadaver : package fixes security vulnerability in neon
Status: RESOLVED FIXED
Alias: None
Product: Gentoo Security
Classification: Unclassified
Component: GLSA Errors (show other bugs)
Hardware: All All
: Highest normal (vote)
Assignee: Gentoo Security
URL: http://cve.mitre.org/cgi-bin/cvename....
Whiteboard:
Keywords:
Depends on:
Blocks:
 
Reported: 2004-04-14 08:27 UTC by gen2daniel
Modified: 2004-04-19 02:39 UTC (History)
0 users

See Also:
Package list:
Runtime testing required: ---
plasmaroo: Pending+


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description gen2daniel 2004-04-14 08:27:29 UTC
cadaver is a command-line WebDAV client that uses inbuilt code from neon,
an HTTP and WebDAV client library.

Versions of the neon client library up to and including 0.24.4 have been
found to contain a number of format string bugs.  An attacker could create
a malicious WebDAV server in such a way as to allow arbitrary code
execution on the client should a user connect to it using cadaver.  The
Common Vulnerabilities and Exposures project (cve.mitre.org) has assigned
the name CAN-2004-0179 to this issue.
Comment 1 Thierry Carrez (RETIRED) gentoo-dev 2004-04-14 12:43:08 UTC
Confirmed.
Fix is in cadaver 0.22.1
No metadata -- and latest dev (sethbc) is now inactive.
Any idea who could do it ?
Comment 2 Tim Yamin (RETIRED) gentoo-dev 2004-04-14 12:51:02 UTC
Done and stable on X86. Ready for a GLSA.
Comment 3 Thierry Carrez (RETIRED) gentoo-dev 2004-04-19 02:39:32 UTC
GLSA 200404-14 is out -- closing