Free and open-source vulnerability scanner
Mageni eases for you the vulnerability scanning, assessment, and management process. It is free and open-source.
Install NowAvailable for macOS, Windows, and Linux
Gentoo Security Advisory GLSA 200405-15 (cadaver)
Information
Severity
Severity
Family
Family
CVSSv2 Base
CVSSv2 Base
CVSSv2 Vector
CVSSv2 Vector
Solution Type
Solution Type
Created
Created
Modified
Modified
Summary
The remote host is missing updates announced in advisory GLSA 200405-15.
Insight
Insight
There is a heap-based buffer overflow vulnerability in the neon library used in cadaver, possibly leading to execution of arbitrary code when connected to a malicious server.
Solution
Solution
All users of cadaver should upgrade to the latest stable version: # emerge sync # emerge -pv '>=net-misc/cadaver-0.22.2' # emerge '>=net-misc/cadaver-0.22.2' http://www.securityspace.com/smysecure/catid.html?in=GLSA%20200405-15 http://bugs.gentoo.org/show_bug.cgi?id=51461 http://www.gentoo.org/security/en/glsa/glsa-200405-13.xml