CVE-2004-0398
Summary
| CVE | CVE-2004-0398 |
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2004-07-07 04:00:00 UTC |
| Updated | 2020-10-09 17:06:00 UTC |
| Description | Heap-based buffer overflow in the ne_rfc1036_parse date parsing function for the neon library (libneon) 0.24.5 and earlier, as used by cadaver before 0.22, allows remote WebDAV servers to execute arbitrary code on the client. |
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|
| redhat.com | Red Hat Support |
REDHAT |
www.redhat.com |
Third Party Advisory |
| 6302 |
OSVDB |
www.osvdb.org |
Broken Link |
| O-148: Linux Neon and Cadaver Buffer Overflow Vulnerability |
CIAC |
www.ciac.org |
Broken Link |
| Secunia - Advisories - Gentoo update for neon |
SECUNIA |
secunia.com |
Third Party Advisory |
| IBM X-Force Exchange |
XF |
exchange.xforce.ibmcloud.com |
Third Party Advisory, VDB Entry |
| Neohapsis Archives - Full Disclosure List - #0982 - [Full-Disclosure] Advisory 06/2004: libneon date parsing vulnerability |
FULLDISC |
archives.neohapsis.com |
Broken Link |
| Home - Conectiva |
CONECTIVA |
distro.conectiva.com.br |
Broken Link |
| Debian -- Security Information -- DSA-507-1 cadaver |
DEBIAN |
www.debian.org |
Third Party Advisory |
| Advisories - Mandriva |
MANDRAKE |
www.mandriva.com |
Third Party Advisory |
| FEDORA-2004-1552 |
FEDORA |
bugzilla.fedora.us |
Broken Link |
| Gentoo Linux Documentation
--
cadaver heap-based buffer overflow |
GENTOO |
security.gentoo.org |
Third Party Advisory |
| Debian -- Security Information -- DSA-506-1 neon |
DEBIAN |
www.debian.org |
Third Party Advisory |
| '[OpenPKG-SA-2004.024] OpenPKG Security Advisory (neon)' - MARC |
BUGTRAQ |
marc.info |
Third Party Advisory |
| 'Advisory 06/2004: libneon date parsing vulnerability' - MARC |
BUGTRAQ |
marc.info |
Third Party Advisory |
| Secunia - Advisories - Neon Date Parsing Heap Overflow Vulnerability |
SECUNIA |
secunia.com |
Third Party Advisory |
| Neon WebDAV Client Library ne_rfc1036_parse Function Heap Overflow Vulnerability |
BID |
www.securityfocus.com |
Third Party Advisory, VDB Entry |
| Gentoo Linux Documentation
--
neon heap-based buffer overflow |
GENTOO |
security.gentoo.org |
Third Party Advisory |
| Secunia - Advisories - Debian update for libneon |
SECUNIA |
secunia.com |
Third Party Advisory |
| CVE Program record |
CVE.ORG |
www.cve.org |
canonical |
| NVD vulnerability detail |
NVD |
nvd.nist.gov |
canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 900131 CBL-Mariner Linux Security Update for subversion 1.14.0
- 900132 CBL-Mariner Linux Security Update for c-ares 1.14.0