Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 544
Alerts This Week
Warning Icon 1 544

Gentoo GLSA-200404-14 Normal: Cadaver Format String Code Execution

gentoo
Calendar Grey April 19, 2004
Scroller Gentoo
Numerous format string weaknesses in cadaver could result in arbitrary code execution. Gentoo advisory GLSA 200404-14.
There are multiple format string vulnerabilities in the neon library used in cadaver, possibly leading to execution of arbitrary code when connected to a malicious server

Summary

Gentoo Linux Security Advisory GLSA 200404-14 https://security.gentoo.org/ Severity: Normal Title: Multiple format string vulnerabilities in cadaver
Date: April 19, 2004 Bugs: #47799 ID: 200404-14

Synopsis ======= There are multiple format string vulnerabilities in the neon library used in cadaver, possibly leading to execution of arbitrary code when connected to a malicious server.
Background ========= According to http://www.webdav.org/cadaver/ cadaver is a command-line WebDAV client for Unix. It supports file upload, download, on-screen display, namespace operations (move/copy), collection creation and deletion, and locking operations.
Affected packages ================ ------------------------------------------------------------------- Package / Vulnerable / Unaffected ----------------------------...

Read the Full Advisory

Resolution

References

Availability

style>.gentoo_availability{display:block;}

Concerns

Synopsis

Background

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Affected Packages

Impact

Workaround