Upstream information

CVE-2008-3746 at MITRE

Description

neon 0.28.0 through 0.28.2 allows remote servers to cause a denial of service (NULL pointer dereference and crash) via vectors related to Digest authentication, Digest domain parameter support, and the parse_domain function.

SUSE information

Overall state of this security issue: Resolved

This issue is currently rated as having important severity.

CVSS v2 Scores
  National Vulnerability Database
Base Score 4.3
Vector AV:N/AC:M/Au:N/C:N/I:N/A:P
Access Vector Network
Access Complexity Medium
Authentication None
Confidentiality Impact None
Integrity Impact None
Availability Impact Partial
SUSE Bugzilla entry: 419075 [RESOLVED / FIXED]

SUSE Security Advisories:

List of released packages

Product(s) Fixed package version(s) References
SUSE Linux Enterprise Server 11 SP1
  • libneon27 >= 0.28.3-2.12.1
  • libneon27-32bit >= 0.28.3-2.12.1
  • libneon27-x86 >= 0.28.3-2.12.1
  • neon >= 0.28.3-2.12.1
Patchnames:
SUSE Linux Enterprise Server 11 SP1 GA libneon27
SUSE Linux Enterprise Server 11 SP2
  • libneon27 >= 0.29.6-6.7.1
  • libneon27-32bit >= 0.29.6-6.7.1
  • libneon27-x86 >= 0.29.6-6.7.1
Patchnames:
SUSE Linux Enterprise Server 11 SP2 GA libneon27
SUSE Linux Enterprise Server 11 SP3
  • libneon27 >= 0.29.6-6.7.1
  • libneon27-32bit >= 0.29.6-6.7.1
  • libneon27-x86 >= 0.29.6-6.7.1
Patchnames:
SUSE Linux Enterprise Server 11 SP3 GA libneon27
SUSE Linux Enterprise Server 11 SP4
  • libneon27 >= 0.29.6-6.7.1
  • libneon27-32bit >= 0.29.6-6.7.1
  • libneon27-x86 >= 0.29.6-6.7.1
Patchnames:
SUSE Linux Enterprise Server 11 SP4 GA libneon27
SUSE Linux Enterprise Software Development Kit 11 SP4
  • libneon-devel >= 0.29.6-6.7.1
  • libneon27-32bit >= 0.29.6-6.7.1
Patchnames:
SUSE Linux Enterprise Software Development Kit 11 SP4 GA libneon-devel
openSUSE 11.0
  • neon-debuginfo >= 0.28.2-17.2
  • neon-debugsource >= 0.28.2-17.2
openSUSE 11.0
  • libneon-devel >= 0.28.2-17.2
  • libneon27 >= 0.28.2-17.2
  • libneon27-32bit >= 0.28.2-17.2
  • libneon27-64bit >= 0.28.2-17.2
  • neon >= 0.28.2-17.2