First published: Thu May 20 2004(Updated: )
Heap-based buffer overflow in the ne_rfc1036_parse date parsing function for the neon library (libneon) 0.24.5 and earlier, as used by cadaver before 0.22, allows remote WebDAV servers to execute arbitrary code on the client.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Neon WebDAV | <=0.24.5 | |
WebDAV Cadaver | <0.22.0 | |
Debian Debian Linux | =3.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2004-0398 has a high severity due to its potential for remote code execution from WebDAV servers.
To fix CVE-2004-0398, upgrade the neon library to version 0.25.0 or later.
CVE-2004-0398 affects neon library versions up to 0.24.5 and cadaver versions before 0.22.0.
CVE-2004-0398 is a heap-based buffer overflow vulnerability.
Yes, CVE-2004-0398 can be exploited remotely by malicious WebDAV servers.