Bug 162318 - net-misc/neon: a denial of service (crash) via a URI with non-ASCII characters (CVE-2007-0157)
Bug#: 162318 Product:  Gentoo Linux Version: unspecified Platform: All
OS/Version: Linux Status: RESOLVED Severity: normal Priority: P2
Resolution: FIXED Assigned To: pauldv@gentoo.org Reported By: kalin@ThinRope.net
Component: Applications
URL:  http://nvd.nist.gov/nvd.cfm?cvename=CVE-2007-0157
Summary: net-misc/neon: a denial of service (crash) via a URI with non-ASCII characters (CVE-2007-0157)
Keywords:  
Status Whiteboard: 
Opened: 2007-01-16 04:13 0000
Description:   Opened: 2007-01-16 04:13 0000
Please see the URL.

Reproducible: Didn't try

Steps to Reproduce:




Patch available here:

http://bugs.debian.org/cgi-bin/bugreport.cgi/neon26_0.26.2-3_to_mdx1.diff?bug=404723;msg=5;att=2

Is this upstream?
Do we need GLSA for that?

------- Comment #1 From Raphael Marichez 2007-01-17 22:46:54 0000 -------
it's a client-side DoS, usually we don't handle client-side DoS since a bad URI
is also a form of disruption of service.

But thanks a lot for the report, Kalin. Reassigning to the maintainer as a
non-security bug.

------- Comment #2 From Raphael Marichez 2007-01-17 22:52:03 0000 -------
And reassiging. Paul is not the real maintainer, but... who else?

There is no upstream fixed release according to http://www.webdav.org/neon/

A proposed patch is provided in the debian bug
http://bugs.debian.org/cgi-bin/bugreport.cgi/neon26_0.26.2-3_to_mdx1.diff?bug=404723;msg=5;att=2

Paul, act as you want :)

------- Comment #3 From Carsten Lohrke 2007-05-14 13:47:48 0000 -------
bumped to 0.26.3 at least

------- Comment #4 From Benedikt Böhm 2007-11-10 19:40:04 0000 -------
fixed in 0.26.4