CVE-2008-3746: Null Pointer Dereference
Published Aug 27, 2008
·Updated
neon 0.28.0 through 0.28.2 allows remote servers to cause a denial of service (NULL pointer dereference and crash) via vectors related to Digest authentication, Digest domain parameter support, and the parsedomain function.
Affected Software
3 affected components
WebDAV neon=0.28.2
WebDAV neon=0.28.0
WebDAV neon=0.28.1
Remediation
Event History
Aug 27, 2008
CVE Published
via MITRE·03:00 PM
Data Sourced
via MITRE·03:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2008-3746?
CVE-2008-3746 has a medium severity level due to its potential to cause a denial of service.
2
How do I fix CVE-2008-3746?
To fix CVE-2008-3746, upgrade to Neon versions 0.28.3 or later where the vulnerability has been patched.
3
What software versions are affected by CVE-2008-3746?
CVE-2008-3746 affects Neon WebDAV versions 0.28.0 through 0.28.2.
4
What kind of attack does CVE-2008-3746 enable?
CVE-2008-3746 enables remote servers to exploit the vulnerability, leading to a denial of service by causing a null pointer dereference.
5
Is there a workaround for CVE-2008-3746?
There is no confirmed workaround for CVE-2008-3746; updating to a patched version is recommended.