LWN.net Logo

neon: denial of service, man in the middle attack

Package(s):neon CVE #(s):CVE-2009-2473
Created:August 21, 2009 Updated:January 17, 2013
Description: From the Fedora advisory: There are two security issues in neon: the "billion laughs" attack against expat could allow a Denial of Service attack by a malicious server. (CVE-2009-2473), and an embedded NUL byte in a certificate subject name could allow an undetected MITM attack against an SSL server if a trusted CA issues such a cert.
Alerts:
CentOS CESA-2009:1452 2009-09-22
Red Hat RHSA-2009:1452-01 2009-09-21
SuSE SUSE-SR:2009:018 2009-11-10
Mandriva MDVSA-2009:221 2009-08-24
Fedora FEDORA-2009-8815 2009-08-20
Fedora FEDORA-2009-8794 2009-08-20
CentOS CESA-2009:1452 2009-10-30
Oracle ELSA-2013-0131 2013-01-12
Scientific Linux SL-gnom-20130116 2013-01-16
CentOS CESA-2013:0131 2013-01-09

(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds