First published: Tue Jan 09 2007(Updated: )
Array index error in the uri_lookup function in the URI parser for neon 0.26.0 to 0.26.2, possibly only on 64-bit platforms, allows remote malicious servers to cause a denial of service (crash) via a URI with non-ASCII characters, which triggers a buffer under-read due to a type conversion error that generates a negative index.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
nCipher | =0.26.0 | |
nCipher | =0.26.1 | |
nCipher | =0.26.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2007-0157 has a medium severity level due to its potential to cause a denial of service.
To fix CVE-2007-0157, update neon to version 0.26.3 or later.
CVE-2007-0157 affects neon versions 0.26.0 to 0.26.2, especially on 64-bit platforms.
CVE-2007-0157 involves remote denial of service attacks via specially crafted URIs containing non-ASCII characters.
Yes, CVE-2007-0157 is reported to be particularly problematic on 64-bit platforms.