oss-sec mailing list archives

CVE request for neon


From: Joe Orton <joe () manyfish co uk>
Date: Fri, 15 Aug 2008 14:45:02 +0100

I haven't had any luck contacting either the Debian maintainer or the 
Debian BTS to update details of this issue.

----- Forwarded message from Joe Orton <joe () manyfish co uk> -----

Hi, can you assign a CVE number for an issue in neon:

A NULL pointer deference in the Digest authentication support in neon 
versions 0.28.0 through 0.28.2 inclusive allows a malicious server to 
crash a client application, resulting in possible denial of service.

Reference: http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=476571

Regards, Joe

----- End forwarded message -----


Current thread: