Vulnerability Assessment & Network Security Forums



If through a vulnerability assessment, a network security issue is detected for the vulnerability below, applying the appropriate security patches in a timely matter is very important.  If you have detected that your system has already been compromised, following CERT's Network Security recovery document will assist with recommended steps for system recovery.


Home >> Browse Vulnerability Assessment Database >> Gentoo Local Security Checks >> [GLSA-200405-25] tla: Multiple vulnerabilities in included libneon


Vulnerability Assessment Details

[GLSA-200405-25] tla: Multiple vulnerabilities in included libneon

Vulnerability Assessment Summary
tla: Multiple vulnerabilities in included libneon

Detailed Explanation for this Vulnerability Assessment
The remote host is affected by the vulnerability described in GLSA-200405-25
(tla: Multiple vulnerabilities in included libneon)


Multiple format string vulnerabilities and a heap overflow vulnerability
were discovered in the code of the neon library (GLSA 200405-01 and
200405-13). Current versions of the tla package include their own version
of this library.

Impact

When connected to a malicious WebDAV server, these vulnerabilities could
permit execution of arbitrary code with the rights of the user running tla.

Workaround

There is no known workaround at this time.

References:
http://www.gentoo.org/security/en/glsa/glsa-200405-01.xml
http://www.gentoo.org/security/en/glsa/glsa-200405-13.xml


Solution:
All users of tla should upgrade to the latest stable version:
# emerge sync
# emerge -pv ">=dev-util/tla-1.2-r2"
# emerge ">=dev-util/tla-1.2-r2"


Network Security Threat Level: Medium


Networks Security ID:

Vulnerability Assessment Copyright: (C) 2005 Michel Arboi

Cables, Connectors


Dell R640 8x 2.5

Dell R640 8x 2.5" SFF iDRAC 2x 25GbE SFP28- Wholesale Custom Build Your Server

$259.99



Dell PowerEdge R630 Server 2x E5-2697v3 2.60Ghz 28-Core 128GB H730P Rails picture

Dell PowerEdge R630 Server 2x E5-2697v3 2.60Ghz 28-Core 128GB H730P Rails

$295.00



Dell Poweredge R630 2x Xeon E5-2680 v3 2.5ghz 24-Cores  32gb  180GB SSD  495w picture

Dell Poweredge R630 2x Xeon E5-2680 v3 2.5ghz 24-Cores 32gb 180GB SSD 495w

$169.99



Dell PowerEdge R730XD Server 2x E5-2620 V4=16 Cores | H330 | 32GB RAM | 2x trays picture

Dell PowerEdge R730XD Server 2x E5-2620 V4=16 Cores | H330 | 32GB RAM | 2x trays

$258.99



Dell PowerEdge R630 Server 2x E5-2690v4 2.60Ghz 28-Core 128GB 2x 960GB SSD H730 picture

Dell PowerEdge R630 Server 2x E5-2690v4 2.60Ghz 28-Core 128GB 2x 960GB SSD H730

$398.10



Dell Poweredge R730 2x Xeon E5-2670 v3 2.3ghz 24-Cores 32gb H730 iDracEnt picture

Dell Poweredge R730 2x Xeon E5-2670 v3 2.3ghz 24-Cores 32gb H730 iDracEnt

$174.99



Dell Poweredge R720xd 2x Xeon E5-2690 v2 3GHz 20-Cores  256GB  H710  26x Trays picture

Dell Poweredge R720xd 2x Xeon E5-2690 v2 3GHz 20-Cores 256GB H710 26x Trays

$304.99



Dell PowerEdge R630 Server 8 Bay - Pick RAM Drives RAID PSUs - All Inc 2x12c CPU picture

Dell PowerEdge R630 Server 8 Bay - Pick RAM Drives RAID PSUs - All Inc 2x12c CPU

$310.00



Dell R640 8x 2.5

Dell R640 8x 2.5" SFF Server iDRAC - Wholesale Custom Build Your Server

$260.99



Dell PowerEdge R730XD Server 2x E5-2660 V4 = 28 Cores H730 128GB RAM 4x trays picture

Dell PowerEdge R730XD Server 2x E5-2660 V4 = 28 Cores H730 128GB RAM 4x trays

$368.99



Discussions

No Discussions have been posted on this vulnerability.