CVE-2007-0157

Array index error in the uri_lookup function in the URI parser for neon 0.26.0 to 0.26.2, possibly only on 64-bit platforms, allows remote malicious servers to cause a denial of service (crash) via a URI with non-ASCII characters, which triggers a buffer under-read due to a type conversion error that generates a negative index.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:neon:neon:0.26.2:*:*:*:*:*:*:*
cpe:2.3:a:neon:neon:0.26.0:*:*:*:*:*:*:*
cpe:2.3:a:neon:neon:0.26.1:*:*:*:*:*:*:*

History

07 Nov 2023, 02:00

Type Values Removed Values Added
References
  • {'url': 'http://bugs.debian.org/cgi-bin/bugreport.cgi/neon26_0.26.2-3_to_mdx1.diff?bug=404723;msg=5;att=2', 'name': 'http://bugs.debian.org/cgi-bin/bugreport.cgi/neon26_0.26.2-3_to_mdx1.diff?bug=404723;msg=5;att=2', 'tags': [], 'refsource': 'CONFIRM'}
  • () http://bugs.debian.org/cgi-bin/bugreport.cgi/neon26_0.26.2-3_to_mdx1.diff?bug=404723%3Bmsg=5%3Batt=2 -

Information

Published : 2007-01-09 21:28

Updated : 2023-11-07 02:00


NVD link : CVE-2007-0157

Mitre link : CVE-2007-0157


JSON object : View

Products Affected

neon

  • neon