CVE Vulnerabilities

CVE-2007-0157

Published: Jan 09, 2007 | Modified: Nov 07, 2023
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
7.8 HIGH
AV:N/AC:L/Au:N/C:N/I:N/A:C
RedHat/V2
RedHat/V3
Ubuntu
UNTRIAGED

Array index error in the uri_lookup function in the URI parser for neon 0.26.0 to 0.26.2, possibly only on 64-bit platforms, allows remote malicious servers to cause a denial of service (crash) via a URI with non-ASCII characters, which triggers a buffer under-read due to a type conversion error that generates a negative index.

Affected Software

Name Vendor Start Version End Version
Neon Neon 0.26.0 (including) 0.26.0 (including)
Neon Neon 0.26.1 (including) 0.26.1 (including)
Neon Neon 0.26.2 (including) 0.26.2 (including)
Cadaver Ubuntu dapper *
Cadaver Ubuntu devel *
Cadaver Ubuntu edgy *
Cadaver Ubuntu feisty *
Cadaver Ubuntu gutsy *
Cadaver Ubuntu hardy *
Cadaver Ubuntu intrepid *
Cadaver Ubuntu jaunty *
Cadaver Ubuntu karmic *
Neon26 Ubuntu devel *
Neon26 Ubuntu feisty *
Neon26 Ubuntu gutsy *
Neon26 Ubuntu hardy *
Neon26 Ubuntu intrepid *
Neon26 Ubuntu jaunty *
Neon26 Ubuntu karmic *

References