Summary
The remote host is missing an update to libneon0.27 announced via advisory MDVSA-2009:074.
Solution
To upgrade automatically use MandrakeUpdate or urpmi. The verification of md5 checksums and GPG signatures is performed automatically for you.
https://secure1.securityspace.com/smysecure/catid.html?in=MDVSA-2009:074
Insight
A security vulnerability has been identified and fixed in neon:
neon 0.28.0 through 0.28.2 allows remote servers to cause a denial of service (NULL pointer dereference and crash) via vectors related to Digest authentication and Digest domain parameter support (CVE-2008-3746).
The updated packages have been upgraded to version 0.28.3 to prevent this.
Affected: 2008.1
Severity
Classification
-
CVE CVE-2008-3746 -
CVSS Base Score: 4.3
AV:N/AC:M/Au:N/C:N/I:N/A:P
Related Vulnerabilities