From e6b0545d36a40cce119d3a14e44be8df257cfaa1 Mon Sep 17 00:00:00 2001 From: miwi Date: Fri, 12 Sep 2008 09:12:18 +0000 Subject: - Document neon -- NULL pointer dereference in Digest domain support Approved by: portmgr (secteam blanked) --- security/vuxml/vuln.xml | 31 +++++++++++++++++++++++++++++++ 1 file changed, 31 insertions(+) (limited to 'security') diff --git a/security/vuxml/vuln.xml b/security/vuxml/vuln.xml index 001760fc3937..1f5ad377cfae 100644 --- a/security/vuxml/vuln.xml +++ b/security/vuxml/vuln.xml @@ -34,6 +34,37 @@ Note: Please add new entries to the beginning of this file. --> + + neon -- NULL pointer dereference in Digest domain support + + + neon28 + 0.28.3 + + + + +

Joe Orton reports:

+
+

A NULL pointer deference in the Digest authentication support in + neon versions 0.28.0 through 0.28.2 inclusive allows a malicious + server to crash a client application, resulting in possible denial + of service.

+
+ +
+ + 307110 + CVE-2008-3746 + http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=476571 + http://lists.manyfish.co.uk/pipermail/neon/2008-August/000040.html + + + 2008-08-15 + 2008-09-12 + +
+ clamav -- CHM Processing Denial of Service -- cgit