Fedora Update Notification
FEDORA-2004-130
2004-05-19
---------------------------------------------------------------------

Product     : Fedora Core 2
Name        : neon
Version     : 0.24.5                      
Release     : 2.2                  
Summary     : An HTTP and WebDAV client library
Description :
neon is an HTTP and WebDAV client library, with a C interface;
providing a high-level interface to HTTP and WebDAV methods along
with a low-level interface for HTTP request handling.  neon
supports persistent connections, proxy servers, basic, digest and
Kerberos authentication, and has complete SSL support.

---------------------------------------------------------------------
Update Information:

Stefan Esser discovered a flaw in the neon library which allows a heap
buffer overflow in a date parsing routine. An attacker could create a
malicious WebDAV server in such a way as to allow arbitrary code
execution on the client should a user connect to it using a neon-based
application which uses the date parsing routines, such as cadaver.

The Common Vulnerabilities and Exposures project (cve.mitre.org) has
assigned the name CAN-2004-0398 to this issue.  This update includes
packages with a patch for this issue.

---------------------------------------------------------------------
* Sun May 16 2004 Joe Orton <jorton@redhat.com> 0.24.5-2.2

- rebuild for FC2 update

* Sun May 16 2004 Joe Orton <jorton@redhat.com> 0.24.5-2.1

- add security fix for CVE CAN-2004-0398

---------------------------------------------------------------------
This update can be downloaded from:
    

435cce4188891f20707b16615c893413  SRPMS/neon-0.24.5-2.2.src.rpm
6dece9ed94cbf68834f7d84b6868f4d9  i386/neon-0.24.5-2.2.i386.rpm
d307e0e58a179d12b1c40c840279d6c9  i386/neon-devel-0.24.5-2.2.i386.rpm
4d4b66a4a49c82ed57ce4c00a2b0cebc  i386/debug/neon-debuginfo-0.24.5-2.2.i386.rpm
ab0fb62241d6373f83081580d144cfee  x86_64/neon-0.24.5-2.2.x86_64.rpm
ba481e85f740f718c10fc9e8ccc60f9f  x86_64/neon-devel-0.24.5-2.2.x86_64.rpm
fcab8e5e26dccd7f1f904b0d1379198f  x86_64/debug/neon-debuginfo-0.24.5-2.2.x86_64.rpm

This update can also be installed with the Update Agent; you can
launch the Update Agent with the 'up2date' command.  

-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-

Fedora Update Notification
FEDORA-2004-129
2004-05-19
---------------------------------------------------------------------

Product     : Fedora Core 1
Name        : neon
Version     : 0.24.5                      
Release     : 2.1                  
Summary     : An HTTP and WebDAV client library
Description :
neon is an HTTP and WebDAV client library, with a C interface;
providing a high-level interface to HTTP and WebDAV methods along
with a low-level interface for HTTP request handling.  neon
supports persistent connections, proxy servers, basic, digest and
Kerberos authentication, and has complete SSL support.

---------------------------------------------------------------------
Update Information:

Stefan Esser discovered a flaw in the neon library which allows a heap
buffer overflow in a date parsing routine. An attacker could create a
malicious WebDAV server in such a way as to allow arbitrary code
execution on the client should a user connect to it using a neon-based
application which uses the date parsing routines, such as cadaver.

The Common Vulnerabilities and Exposures project (cve.mitre.org) has
assigned the name CAN-2004-0398 to this issue.  This update includes
packages with a patch for this issue.

---------------------------------------------------------------------
* Sun May 16 2004 Joe Orton <jorton@redhat.com> 0.24.5-2.1

- add security fix for CVE CAN-2004-0398

---------------------------------------------------------------------
This update can be downloaded from:
    

71f0ddffbe8b5171b2fa2d93e55f8e35  SRPMS/neon-0.24.5-2.1.src.rpm
c215af0bae2c90672573090fee1ec706  i386/neon-0.24.5-2.1.i386.rpm
89c59069a0b48258b8b5f8cc66be5bf7  i386/neon-devel-0.24.5-2.1.i386.rpm
f7d813c7a96814072b097f15692771e9  i386/debug/neon-debuginfo-0.24.5-2.1.i386.rpm
841d910930f3def3f0202570b8c984a6  x86_64/neon-0.24.5-2.1.x86_64.rpm
92cc5ffa0588fe59bdd976308ea52971  x86_64/neon-devel-0.24.5-2.1.x86_64.rpm
03c24e6f0cd267e655a40127696a71b6  x86_64/debug/neon-debuginfo-0.24.5-2.1.x86_64.rpm

This update can also be installed with the Update Agent; you can
launch the Update Agent with the 'up2date' command.

Fedora: 2,1: neon Heap overflow vulnerability

May 19, 2004
An attacker could create a malicious WebDAV server in such a way as to allow arbitrary code execution on the client, such as cadaver.

Summary

neon is an HTTP and WebDAV client library, with a C interface;

providing a high-level interface to HTTP and WebDAV methods along

with a low-level interface for HTTP request handling. neon

supports persistent connections, proxy servers, basic, digest and

Kerberos authentication, and has complete SSL support.

neon is an HTTP and WebDAV client library, with a C interface;

providing a high-level interface to HTTP and WebDAV methods along

with a low-level interface for HTTP request handling. neon

supports persistent connections, proxy servers, basic, digest and

Kerberos authentication, and has complete SSL support.

Update Information:

Stefan Esser discovered a flaw in the neon library which allows a heap buffer overflow in a date parsing routine. An attacker could create a malicious WebDAV server in such a way as to allow arbitrary code execution on the client should a user connect to it using a neon-based application which uses the date parsing routines, such as cadaver.

The Common Vulnerabilities and Exposures project (cve.mitre.org) has assigned the name CAN-2004-0398 to this issue. This update includes packages with a patch for this issue.

* Sun May 16 2004 Joe Orton <jorton@redhat.com> 0.24.5-2.2

- rebuild for FC2 update

* Sun May 16 2004 Joe Orton <jorton@redhat.com> 0.24.5-2.1

- add security fix for CVE CAN-2004-0398

This update can be downloaded from:


435cce4188891f20707b16615c893413 SRPMS/neon-0.24.5-2.2.src.rpm 6dece9ed94cbf68834f7d84b6868f4d9 i386/neon-0.24.5-2.2.i386.rpm d307e0e58a179d12b1c40c840279d6c9 i386/neon-devel-0.24.5-2.2.i386.rpm 4d4b66a4a49c82ed57ce4c00a2b0cebc i386/debug/neon-debuginfo-0.24.5-2.2.i386.rpm ab0fb62241d6373f83081580d144cfee x86_64/neon-0.24.5-2.2.x86_64.rpm ba481e85f740f718c10fc9e8ccc60f9f x86_64/neon-devel-0.24.5-2.2.x86_64.rpm fcab8e5e26dccd7f1f904b0d1379198f x86_64/debug/neon-debuginfo-0.24.5-2.2.x86_64.rpm

This update can also be installed with the Update Agent; you can launch the Update Agent with the 'up2date' command.

-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-

Fedora Update Notification FEDORA-2004-129 2004-05-19

Product : Fedora Core 1 Name : neon Version : 0.24.5 Release : 2.1 Summary : An HTTP and WebDAV client library Description : neon is an HTTP and WebDAV client library, with a C interface; providing a high-level interface to HTTP and WebDAV methods along with a low-level interface for HTTP request handling. neon supports persistent connections, proxy servers, basic, digest and Kerberos authentication, and has complete SSL support.


Stefan Esser discovered a flaw in the neon library which allows a heap buffer overflow in a date parsing routine. An attacker could create a malicious WebDAV server in such a way as to allow arbitrary code execution on the client should a user connect to it using a neon-based application which uses the date parsing routines, such as cadaver.

The Common Vulnerabilities and Exposures project (cve.mitre.org) has assigned the name CAN-2004-0398 to this issue. This update includes packages with a patch for this issue.

* Sun May 16 2004 Joe Orton <jorton@redhat.com> 0.24.5-2.1

- add security fix for CVE CAN-2004-0398

This update can be downloaded from:


71f0ddffbe8b5171b2fa2d93e55f8e35 SRPMS/neon-0.24.5-2.1.src.rpm c215af0bae2c90672573090fee1ec706 i386/neon-0.24.5-2.1.i386.rpm 89c59069a0b48258b8b5f8cc66be5bf7 i386/neon-devel-0.24.5-2.1.i386.rpm f7d813c7a96814072b097f15692771e9 i386/debug/neon-debuginfo-0.24.5-2.1.i386.rpm 841d910930f3def3f0202570b8c984a6 x86_64/neon-0.24.5-2.1.x86_64.rpm 92cc5ffa0588fe59bdd976308ea52971 x86_64/neon-devel-0.24.5-2.1.x86_64.rpm 03c24e6f0cd267e655a40127696a71b6 x86_64/debug/neon-debuginfo-0.24.5-2.1.x86_64.rpm

This update can also be installed with the Update Agent; you can launch the Update Agent with the 'up2date' command.

Change Log

References

Fedora Update Notification FEDORA-2004-130 2004-05-19 Product : Fedora Core 2 Name : neon Version : 0.24.5 Release : 2.2 Summary : An HTTP and WebDAV client library Description : neon is an HTTP and WebDAV client library, with a C interface; providing a high-level interface to HTTP and WebDAV methods along with a low-level interface for HTTP request handling. neon supports persistent connections, proxy servers, basic, digest and Kerberos authentication, and has complete SSL support.

Update Instructions

Severity
Product : Fedora Core 2
Name : neon
Version : 0.24.5
Release : 2.2
Summary : An HTTP and WebDAV client library
Product : Fedora Core 1
Name : neon
Version : 0.24.5
Release : 2.1
Summary : An HTTP and WebDAV client library

Related News