Bugzilla – Bug 56833
VUL-0: CVE-2004-0398: libneon: non-filtered control chars
Last modified: 2021-10-11 13:58:23 UTC
Hi Olaf. see bug 56724 comment #6
<!-- SBZ_reproduce --> -
Created attachment 20965 [details] sitecopy-neon-0.23.7.diff
patches submitted for 9.1, 9.0, 8.2 and 8.1
could you make sure that in STABLE the pakcages requiring libneon link against the dynamic lib fromn the system , if possible?
patchinfo?
Created attachment 21131 [details] patchinfo-box.neon
Hmm, that's the neon patchinfo, I meant the sitecopy patchinfo. Do we need a neon update too? Olaf? (And please copy the patchinfo to /work/src/done/PATCHINFO so that we don't have to poll bugzilla...)
Still no sitecopy patchinfo?
Because it's the wrong bug entry... :) bug 56711 The files in the bugzilla are wrong. I'll attach new ones. Olaf can you submit the pacthinfo files after checking in the new packages please.
hmm, I either forgot to copy updated sitecopy packages or someone removed them. copied them again with this patch.
<!-- SBZ_reopen -->Reopened by mls@suse.de at Mon Jun 21 12:53:48 2004, took initial reporter thomas@suse.de to cc
Ok, so what's with the neon package? Don't we need an update for it as well? (It's not included on SLES.) And: a ne_xml.c chunk of the #37716 fix seems to be left out by mistake! (At least in the 8.1 version.) This must be fixed as well.
I have submitted updated neon packages for 9.0, 8.2 and 8.1, they contain the ne_xml.c part.
Do we had patchinfo files for it?
Okay, packages containing the missing hunk checked in. Now back to my first question: Olaf, isn't neon also vulerable to the control char attack? That's what this bugzilla entry is about...
this patch is already in 8.2 neon since 2003-03-01
Great! Then I need the patchinfo files...
I think we already have updated packages on the ftp server: ------------------------------------------------------------------- Thu Apr 1 13:18:41 CEST 2004 - olh@suse.de - add CAN-2004-0179-neon-0.23.9.diff (#37716) Can we reuse the old patchinfo files?
Please add a space somewhere to get another md5 hash...
Olaf, concerning comment #16 we also have the control char path for 8.1 and 8.0? If you reuse the patchinfo files please add a space somewhere to get a new md5 hash. Can this be done ASAP please.... this bug gets a bad smell during the last weeks. ;)
8.0 has no neon. The updated packages are already checked in since 2004-07-09
Olaf, did you submit some patchinfo files?
No, I did not. can we reuse the old ones?
Olaf???? comment #19, comment #20
the packages in 8.1 (as example) are already newer than the one on the ftp server. ftp.suse.com/pub/suse/i386/update/8.1/rpm/i586/neon.rpm | head * Son Mai 09 2004 - olh@suse.de - add neon-CAN-2004-0398.patch (#39774) * Don Apr 01 2004 - olh@suse.de - add CAN-2004-0179-neon-0.23.9.diff (#37716) head neon.changes ------------------------------------------------------------------- Wed Jul 7 15:53:46 CEST 2004 - olh@suse.de - update CAN-2004-0179-neon-0.23.9.diff (#41833) add missing hunks ------------------------------------------------------------------- Sun May 9 17:39:21 CEST 2004 - olh@suse.de - add neon-CAN-2004-0398.patch (#39774)
I submitted them on my own!
Maybe, but what's the point of including 9.1/SLES9? As far as I can tell they already have the fix.
changed in box file removed sles9 patchinfo file
packages approved
CVE-2004-0398: CVSS v2 Base Score: 7.5 (AV:N/AC:L/Au:N/C:P/I:P/A:P)