Debian Neon27 vulnerabilities

3 known vulnerabilities affecting debian/neon27.

Total CVEs
3
CISA KEV
0
Public exploits
1
Exploited in wild
0
Severity breakdown
MEDIUM2LOW1

Vulnerabilities

Page 1 of 1
CVE-2009-2474MEDIUMCVSS 5.9fixed in litmus 0.13-1 (bookworm)2009
CVE-2009-2474 [MEDIUM] CVE-2009-2474: litmus - neon before 0.28.6, when OpenSSL or GnuTLS is used, does not properly handle a '... neon before 0.28.6, when OpenSSL or GnuTLS is used, does not properly handle a '\0' character in a domain name in the subject's Common Name (CN) field of an X.509 certificate, which allows man-in-the-middle attackers to spoof arbitrary SSL servers via a crafted certificate issued by a legitimate Certification Authority, a related issue to CVE-2009-2408. Scope: local
debian
CVE-2009-2473LOWCVSS 6.5PoC2009
CVE-2009-2473 [MEDIUM] CVE-2009-2473: neon27 - neon before 0.28.6, when expat is used, does not properly detect recursion durin... neon before 0.28.6, when expat is used, does not properly detect recursion during entity expansion, which allows context-dependent attackers to cause a denial of service (memory and CPU consumption) via a crafted XML document containing a large number of nested entity references, a similar issue to CVE-2003-1564. Scope: local bookworm: resolved bullseye: resolved for
debian
CVE-2008-3746MEDIUMCVSS 4.3fixed in neon27 0.28.2-4 (bookworm)2008
CVE-2008-3746 [MEDIUM] CVE-2008-3746: neon27 - neon 0.28.0 through 0.28.2 allows remote servers to cause a denial of service (N... neon 0.28.0 through 0.28.2 allows remote servers to cause a denial of service (NULL pointer dereference and crash) via vectors related to Digest authentication, Digest domain parameter support, and the parse_domain function. Scope: local bookworm: resolved (fixed in 0.28.2-4) bullseye: resolved (fixed in 0.28.2-4) forky: resolved (fixed in 0.28.2-4) sid: resolved (fi
debian