neon: denial of service, man in the middle attack
| Package(s): | neon | CVE #(s): | CVE-2009-2473 | ||||||||||||||||||||||||||||||||||||||||
| Created: | August 21, 2009 | Updated: | January 17, 2013 | ||||||||||||||||||||||||||||||||||||||||
| Description: | From the Fedora advisory: There are two security issues in neon: the "billion laughs" attack against expat could allow a Denial of Service attack by a malicious server. (CVE-2009-2473), and an embedded NUL byte in a certificate subject name could allow an undetected MITM attack against an SSL server if a trusted CA issues such a cert. | ||||||||||||||||||||||||||||||||||||||||||
| Alerts: |
| ||||||||||||||||||||||||||||||||||||||||||
