CVE-2004-0398: Buffer Overflow
Published May 20, 2004
·Updated
Heap-based buffer overflow in the nerfc1036parse date parsing function for the neon library (libneon) 0.24.5 and earlier, as used by cadaver before 0.22, allows remote WebDAV servers to execute arbitrary code on the client.
Affected Software
3 affected components
WebDAV neon<=0.24.5
WebDAV Cadaver<0.22.0
Debian Debian Linux=3.0
Event History
May 20, 2004
CVE Published
via MITRE·08:00 AM
Data Sourced
via MITRE·08:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2004-0398?
CVE-2004-0398 has a high severity due to its potential for remote code execution from WebDAV servers.
2
How do I fix CVE-2004-0398?
To fix CVE-2004-0398, upgrade the neon library to version 0.25.0 or later.
3
Which versions are affected by CVE-2004-0398?
CVE-2004-0398 affects neon library versions up to 0.24.5 and cadaver versions before 0.22.0.
4
What type of vulnerability is CVE-2004-0398?
CVE-2004-0398 is a heap-based buffer overflow vulnerability.
5
Can CVE-2004-0398 be exploited remotely?
Yes, CVE-2004-0398 can be exploited remotely by malicious WebDAV servers.