>> neon "parse_domain()" Function Denial of Service Vulnerability
Title : neon "parse_domain()" Function Denial of Service Vulnerability VUPEN ID : VUPEN/ADV-2008-2420 CVE ID : CVE-2008-3746 CWE ID : CWE-476
Rated as : Low Risk
Remotely Exploitable : Yes Locally Exploitable : Yes Release Date : 2008-08-25
Technical Description
A vulnerability has been identified in neon, which could be exploited by attackers to cause a denial of service. This issue is caused by a NULL pointer dereference error in the "parse_domain()" function when processing malformed data, which could allow attackers to cause a vulnerable application to crash bu tricking a user into connecting to a malicious server.