FreeBSD VuXML: Documenting security issues in FreeBSD and the FreeBSD Ports Collection

CVE-2004-0179

This CVE name corresponds to:

Entered Topic
2004-04-15 neon format string vulnerabilities

The following information is adapted from the Common Vulnerabilities and Exposures (CVE) project. CVE and the CVE logo are trademarks of The MITRE Corporation. CVE content is Copyright 2005, The MITRE Corporation.

Details

Type Candidate
Name CVE-2004-0179
Phase Assigned(20040225)

Description

Multiple format string vulnerabilities in (1) neon 0.24.4 and earlier, and other products that use neon including (2) Cadaver, (3) Subversion, and (4) OpenOffice, allow remote malicious WebDAV servers to execute arbitrary code.

References

Source Reference
BUGTRAQ 20040416 void.at - neon format string bugs
DEBIAN DSA-487
FEDORA FEDORA-2004-1552
REDHAT RHSA-2004:157
REDHAT RHSA-2004:158
REDHAT RHSA-2004:159
REDHAT RHSA-2004:160
SGI 20040404-01-U
SUSE SuSE-SA:2004:008
SUSE SuSE-SA:2004:009
BUGTRAQ 20040416 [OpenPKG-SA-2004.016] OpenPKG Security Advisory (neon)
GENTOO GLSA-200405-01
GENTOO GLSA-200405-04
MANDRAKE MDKSA-2004:032
BID 10136
OSVDB 5365
OVAL oval:org.mitre.oval:def:1065
OVAL oval:org.mitre.oval:def:10913
SECUNIA 11363