VulnerabilityModified
CVE-2004-0179
Multiple format string vulnerabilities in (1) neon 0.24.4 and earlier, and other products that use neon including (2) Cadaver, (3) Subversion, and (4) OpenOffice, allow remote malicious WebDAV servers to execute arbitrary code.
MEDIUM 6.8EPSS 11.1%
Does this matter?
EPSS puts the probability of exploitation in the next 30 days at 11.1%, higher than 96% of all known CVEs. Patch or mitigate before the next change window.
Description
Multiple format string vulnerabilities in (1) neon 0.24.4 and earlier, and other products that use neon including (2) Cadaver, (3) Subversion, and (4) OpenOffice, allow remote malicious WebDAV servers to execute arbitrary code.
- CVSS 2.0
- 6.8 MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
- EPSS
- 11.06% probability · 96th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-134
- Affected
- webdav/neon · debian/debian linux
- Source
- cve@mitre.org
References
- ftp://patches.sgi.com/support/free/security/advisories/20040404-01-U.ascBroken Link
- http://lists.suse.com/archive/suse-security-announce/2004-Apr/0002.htmlBroken Link
- http://lists.suse.com/archive/suse-security-announce/2004-Apr/0003.htmlBroken Link
- http://marc.info/?l=bugtraq&m=108213873203477&w=2Issue Tracking, Third Party Advisory
- http://marc.info/?l=bugtraq&m=108214147022626&w=2Issue Tracking, Third Party Advisory
- http://secunia.com/advisories/11363Third Party Advisory
- http://security.gentoo.org/glsa/glsa-200405-01.xmlThird Party Advisory
- http://security.gentoo.org/glsa/glsa-200405-04.xmlThird Party Advisory
- http://www.debian.org/security/2004/dsa-487Third Party Advisory
- http://www.mandriva.com/security/advisories?name=MDKSA-2004:032Third Party Advisory
- http://www.osvdb.org/5365Broken Link
- http://www.redhat.com/support/errata/RHSA-2004-157.htmlThird Party Advisory
- http://www.redhat.com/support/errata/RHSA-2004-158.htmlThird Party Advisory
- http://www.redhat.com/support/errata/RHSA-2004-159.htmlThird Party Advisory
- http://www.redhat.com/support/errata/RHSA-2004-160.htmlThird Party Advisory
- http://www.securityfocus.com/bid/10136Third Party Advisory, VDB Entry
- https://bugzilla.fedora.us/show_bug.cgi?id=1552Broken Link
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1065Third Party Advisory
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10913Third Party Advisory
- ftp://patches.sgi.com/support/free/security/advisories/20040404-01-U.ascBroken Link
- http://lists.suse.com/archive/suse-security-announce/2004-Apr/0002.htmlBroken Link
- http://lists.suse.com/archive/suse-security-announce/2004-Apr/0003.htmlBroken Link
- http://marc.info/?l=bugtraq&m=108213873203477&w=2Issue Tracking, Third Party Advisory
- http://marc.info/?l=bugtraq&m=108214147022626&w=2Issue Tracking, Third Party Advisory
- http://secunia.com/advisories/11363Third Party Advisory
- http://security.gentoo.org/glsa/glsa-200405-01.xmlThird Party Advisory
- http://security.gentoo.org/glsa/glsa-200405-04.xmlThird Party Advisory
- http://www.debian.org/security/2004/dsa-487Third Party Advisory
- http://www.mandriva.com/security/advisories?name=MDKSA-2004:032Third Party Advisory
- http://www.osvdb.org/5365Broken Link
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.