Neon < 0.24.5 WebDAV Client Library Format String Vulnerabilities (deprecated)

high Nessus Network Monitor Plugin ID 1779

Synopsis

The remote host is using software based on a vulnerable version of the Neon Library, an open-source HTTP and WebDAV client library.

Description

The remote host is using software based on a vulnerable version of the Neon Library, an open-source HTTP and WebDAV client library. An attacker running a malicious WebDAV server may execute arbitrary code on the host.

Solution

Upgrade to Neon library 0.24.5 or higher.

Plugin Details

Severity: High

ID: 1779

Family: Web Clients

Published: 8/20/2004

Updated: 9/16/2018

Risk Information

VPR

Risk Factor: Medium

Score: 6.6

Reference Information

CVE: CVE-2004-0179, CVE-2004-0398

BID: 10136, 10385