cadaver heap-based buffer overflow
1.
Gentoo Linux Security Advisory
Version Information
| Advisory Reference |
GLSA 200405-15 / cadaver |
| Release Date |
May 20, 2004 |
| Latest Revision |
May 20, 2004: 01 |
| Impact |
normal |
| Exploitable |
remote |
| Package |
Vulnerable versions |
Unaffected versions |
Architecture(s) |
| net-misc/cadaver |
<=
0.22.1 |
>=
0.22.2 |
All supported architectures
|
Related bugreports:
#51461
Synopsis
There is a heap-based buffer overflow vulnerability in the neon library
used in cadaver, possibly leading to execution of arbitrary code when
connected to a malicious server.
2.
Impact Information
Background
cadaver is a command-line WebDAV client.
Description
Stefan Esser discovered a vulnerability in the code of the neon library
(see GLSA 200405-13). This library is also included in cadaver.
Impact
When connected to a malicious WebDAV server, this vulnerability could allow
remote execution of arbitrary code with the rights of the user running
cadaver.
3.
Resolution Information
Workaround
There is no known workaround at this time. All users are advised to upgrade
to the latest available version of cadaver.
Resolution
All users of cadaver should upgrade to the latest stable version:
Code Listing 3.1: Resolution |
# emerge sync
# emerge -pv ">=net-misc/cadaver-0.22.2"
# emerge ">=net-misc/cadaver-0.22.2"
|
4.
References
|