Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 524
Alerts This Week
Warning Icon 1 524

Fedora 10 FEDORA-2009-8794 Moderate: SSL and DoS Issues

fedora
Calendar Grey August 20, 2009
Scroller Fedora
The most recent release of Fedora neon focuses on improving security measures and resolving bugs to boost overall system performance.
This update includes the latest release of neon, version 0.28.6

Summary

neon is an HTTP and WebDAV client library, with a C interface;

providing a high-level interface to HTTP and WebDAV methods along

with a low-level interface for HTTP request handling. neon

supports persistent connections, proxy servers, basic, digest and

Kerberos authentication, and has complete SSL support.

Update Information:

This update includes the latest release of neon, version 0.28.6. This fixes two security issues: * the "billion laughs" attack against expat could allow a Denial of Service attack by a malicious server. (CVE-2009-2473) * an embedded NUL byte in a certificate subject name could allow an undetected MITM attack against an SSL server if a trusted CA issues such a cert. Several bug fixes are also included, notably: * X.509v1 CA certificates are trusted by default * Fix handling of some PKCS#12 certificates

Change Log

* Wed Aug 19 2009 Joe Orton 0.28.6-1 - update to 0.28.6 * Fri May 29 2009 Joe Orton 0.28.4-1.1 - trust V1 CA certs by default (#502451) * Fri Mar 6 2009 Joe Orton 0.28.4-1 - update to 0.28.4 * Mon Jan 19 2009 Joe Orton 0.28.3-3 - use install-p in "make install" (Robert Scheck, #226189)

References


[ 1 ] Bug #502451 - X509v1 CA certificate is not trusted https://bugzilla.redhat.com/show_bug.cgi?id=502451

Update Instructions

This update can be installed with the "yum" update program. Use su -c 'yum update neon' at the command line. For more information, refer to "Managing Software with yum", available at .

Severity
important
Lowest
Low
Medium
High
Critical

Name: neon
Product: Fedora 10
Version: 0.28.6
Release: 1.fc10
URL:
Summary: An HTTP and WebDAV client library

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.