Bug 234826 - net-misc/neon-0.28.2: NULL pointer dereference (CVE-2008-3746)
|
Bug#:
234826
(CVE-2008-3746)
|
Product: Gentoo Security
|
Version: unspecified
|
Platform: All
|
|
OS/Version: Linux
|
Status: RESOLVED
|
Severity: trivial
|
Priority: P2
|
|
Resolution: FIXED
|
Assigned To: security@gentoo.org
|
Reported By: hanno@gentoo.org
|
|
Component: Vulnerabilities
|
|
|
URL:
http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=476571
|
|
Summary: net-misc/neon-0.28.2: NULL pointer dereference (CVE-2008-3746)
|
|
Keywords:
|
|
Status Whiteboard: ~3 [noglsa]
|
|
Opened: 2008-08-15 14:26 0000
|
A NULL pointer deference in the Digest authentication support in neon
versions 0.28.0 through 0.28.2 inclusive allows a malicious server to
crash a client application, resulting in possible denial of service.
Reference: http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=476571
0.26 seems unaffected, CVE is requested on oss-security.
Client crashes are not subject to Vulnerability Treatment Policy, but I'll bite
that subversion might be used in automated setups.
net-misc/neon-0.28.3 was released on 2008-08-20. It fixes CVE-2008-3746.
0.28.3 in cvs, 0.26.4 does not seem to be affected