CVE Vulnerabilities

CVE-2004-0179

Use of Externally-Controlled Format String

Published: Jun 01, 2004 | Modified: Apr 03, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
6.8 MEDIUM
AV:N/AC:M/Au:N/C:P/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

Multiple format string vulnerabilities in (1) neon 0.24.4 and earlier, and other products that use neon including (2) Cadaver, (3) Subversion, and (4) OpenOffice, allow remote malicious WebDAV servers to execute arbitrary code.

Weakness

The product uses a function that accepts a format string as an argument, but the format string originates from an external source.

Affected Software

NameVendorStart VersionEnd Version
NeonWebdav0.19.0 (including)0.24.5 (excluding)
Red Hat Enterprise Linux 3RedHatopenoffice.org-0:1.1.0-15.EL*
Red Hat Enterprise Linux AS (Advanced Server) version 2.1RedHat*
Red Hat Enterprise Linux ES version 2.1RedHat*
Red Hat Enterprise Linux WS version 2.1RedHat*
Red Hat Linux 9RedHat*
Red Hat Linux 9RedHat*
Red Hat Linux 9RedHat*
Red Hat Linux Advanced Workstation 2.1RedHat*
BazaarUbuntudapper*
BazaarUbuntudevel*
BazaarUbuntuedgy*
BazaarUbuntufeisty*
NeonUbuntudapper*
NeonUbuntudevel*
NeonUbuntuedgy*
NeonUbuntufeisty*
Neon24Ubuntudapper*
Neon24Ubuntuedgy*
Neon26Ubuntudevel*
Neon26Ubuntufeisty*
Openoffice.orgUbuntudapper*
Openoffice.orgUbuntuedgy*
Openoffice.orgUbuntufeisty*
Openoffice.org-l10nUbuntudapper*
Openoffice.org-l10nUbuntudevel*
Openoffice.org-l10nUbuntuedgy*
Openoffice.org-l10nUbuntufeisty*
TlaUbuntudapper*
TlaUbuntudevel*
TlaUbuntuedgy*
TlaUbuntufeisty*

Potential Mitigations

References