CVE-2009-2473: Medium severity neon webdav vulnerability
neon before 0.28.6, when expat is used, does not properly detect recursion during entity expansion, which allows context-dependent attackers to cause a denial of service (memory and CPU consumption) via a crafted XML document containing a large number of nested entity references, a similar issue to CVE-2003-1564.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2009-2473?
CVE-2009-2473 has a severity that can lead to denial of service through excessive memory and CPU consumption.
How do I fix CVE-2009-2473?
To fix CVE-2009-2473, upgrade to neon version 0.28.6 or later.
What types of attacks are possible with CVE-2009-2473?
CVE-2009-2473 allows context-dependent attackers to exploit the vulnerability through crafted XML documents.
Which software versions are affected by CVE-2009-2473?
CVE-2009-2473 affects neon versions before 0.28.6 when using expat.
What is the main issue in CVE-2009-2473?
The main issue in CVE-2009-2473 is the improper detection of recursion during entity expansion in XML handling.