CVE-2007-0157

Array index error in the uri_lookup function in the URI parser for neon 0.26.0 to 0.26.2, possibly only on 64-bit platforms, allows remote malicious servers to cause a denial of service (crash) via a URI with non-ASCII characters, which triggers a buffer under-read due to a type conversion error that generates a negative index.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:neon:neon:0.26.0:*:*:*:*:*:*:*
cpe:2.3:a:neon:neon:0.26.1:*:*:*:*:*:*:*
cpe:2.3:a:neon:neon:0.26.2:*:*:*:*:*:*:*

History

21 Nov 2024, 00:25

Type Values Removed Values Added
References () http://bugs.debian.org/cgi-bin/bugreport.cgi/neon26_0.26.2-3_to_mdx1.diff?bug=404723%3Bmsg=5%3Batt=2 - () http://bugs.debian.org/cgi-bin/bugreport.cgi/neon26_0.26.2-3_to_mdx1.diff?bug=404723%3Bmsg=5%3Batt=2 -
References () http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=404723 - () http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=404723 -
References () http://mailman.webdav.org/pipermail/cadaver/2007-January/001015.html - () http://mailman.webdav.org/pipermail/cadaver/2007-January/001015.html -
References () http://mailman.webdav.org/pipermail/neon/2007-January/002362.html - () http://mailman.webdav.org/pipermail/neon/2007-January/002362.html -
References () http://osvdb.org/39247 - () http://osvdb.org/39247 -
References () http://secunia.com/advisories/23751 - () http://secunia.com/advisories/23751 -
References () http://secunia.com/advisories/23763 - () http://secunia.com/advisories/23763 -
References () http://secunia.com/advisories/23984 - () http://secunia.com/advisories/23984 -
References () http://www.mandriva.com/security/advisories?name=MDKSA-2007:013 - () http://www.mandriva.com/security/advisories?name=MDKSA-2007:013 -
References () http://www.novell.com/linux/security/advisories/2007_02_sr.html - () http://www.novell.com/linux/security/advisories/2007_02_sr.html -
References () http://www.securityfocus.com/bid/22035 - () http://www.securityfocus.com/bid/22035 -
References () http://www.vupen.com/english/advisories/2007/0172 - () http://www.vupen.com/english/advisories/2007/0172 -
References () http://www.vupen.com/english/advisories/2007/0362 - () http://www.vupen.com/english/advisories/2007/0362 -
References () http://www.webdav.org/cadaver/ - () http://www.webdav.org/cadaver/ -

Information

Published : 2007-01-09 21:28

Updated : 2025-04-09 00:30


NVD link : CVE-2007-0157

Mitre link : CVE-2007-0157

CVE.ORG link : CVE-2007-0157


JSON object : View

Products Affected

neon

  • neon