[SECURITY] Fedora Core 1 Update: neon-0.24.5-2.1

Joe Orton jorton at redhat.com
Wed May 19 16:06:31 UTC 2004


---------------------------------------------------------------------
Fedora Update Notification
FEDORA-2004-129
2004-05-19
---------------------------------------------------------------------

Product     : Fedora Core 1
Name        : neon
Version     : 0.24.5                      
Release     : 2.1                  
Summary     : An HTTP and WebDAV client library
Description :
neon is an HTTP and WebDAV client library, with a C interface;
providing a high-level interface to HTTP and WebDAV methods along
with a low-level interface for HTTP request handling.  neon
supports persistent connections, proxy servers, basic, digest and
Kerberos authentication, and has complete SSL support.

---------------------------------------------------------------------
Update Information:

Stefan Esser discovered a flaw in the neon library which allows a heap
buffer overflow in a date parsing routine. An attacker could create a
malicious WebDAV server in such a way as to allow arbitrary code
execution on the client should a user connect to it using a neon-based
application which uses the date parsing routines, such as cadaver.

The Common Vulnerabilities and Exposures project (cve.mitre.org) has
assigned the name CAN-2004-0398 to this issue.  This update includes
packages with a patch for this issue.

---------------------------------------------------------------------
* Sun May 16 2004 Joe Orton <jorton at redhat.com> 0.24.5-2.1

- add security fix for CVE CAN-2004-0398

---------------------------------------------------------------------
This update can be downloaded from:
  http://download.fedora.redhat.com/pub/fedora/linux/core/updates/1/

71f0ddffbe8b5171b2fa2d93e55f8e35  SRPMS/neon-0.24.5-2.1.src.rpm
c215af0bae2c90672573090fee1ec706  i386/neon-0.24.5-2.1.i386.rpm
89c59069a0b48258b8b5f8cc66be5bf7  i386/neon-devel-0.24.5-2.1.i386.rpm
f7d813c7a96814072b097f15692771e9  i386/debug/neon-debuginfo-0.24.5-2.1.i386.rpm
841d910930f3def3f0202570b8c984a6  x86_64/neon-0.24.5-2.1.x86_64.rpm
92cc5ffa0588fe59bdd976308ea52971  x86_64/neon-devel-0.24.5-2.1.x86_64.rpm
03c24e6f0cd267e655a40127696a71b6  x86_64/debug/neon-debuginfo-0.24.5-2.1.x86_64.rpm

This update can also be installed with the Update Agent; you can
launch the Update Agent with the 'up2date' command.  
---------------------------------------------------------------------







More information about the fedora-announce-list mailing list