Fedora 11 : neon-0.28.6-1.fc11 (2009-8815)
Medium Nessus Plugin ID 40683
SynopsisThe remote Fedora host is missing a security update.
DescriptionThis update includes the latest release of neon, version 0.28.6. This fixes two security issues: * the 'billion laughs' attack against expat could allow a Denial of Service attack by a malicious server.
(CVE-2009-2473) * an embedded NUL byte in a certificate subject name could allow an undetected MITM attack against an SSL server if a trusted CA issues such a cert.
Note that Tenable Network Security has extracted the preceding description block directly from the Fedora security advisory. Tenable has attempted to automatically clean and format it as much as possible without introducing additional issues.
SolutionUpdate the affected neon package.