« Volver al listado

CVE-2007-0157

Estado: ModificadaAlta (7.8)—

Array index error in the uri_lookup function in the URI parser for neon 0.26.0 to 0.26.2, possibly only on 64-bit platforms, allows remote malicious servers to cause a denial of service (crash) via a URI with non-ASCII characters, which triggers a buffer under-read due to a type conversion error that generates a negative index.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2007-0157",
  "cveTags": [],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 7.8,
          "accessVector": "NETWORK",
          "vectorString": "AV:N/AC:L/Au:N/C:N/I:N/A:C",
          "authentication": "NONE",
          "integrityImpact": "NONE",
          "accessComplexity": "LOW",
          "availabilityImpact": "COMPLETE",
          "confidentialityImpact": "NONE"
        },
        "acInsufInfo": false,
        "impactScore": 6.9,
        "baseSeverity": "HIGH",
        "obtainAllPrivilege": false,
        "exploitabilityScore": 10,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": false,
        "userInteractionRequired": false
      }
    ]
  },
  "affected": [
    {
      "source": "cve@mitre.org",
      "affectedData": [
        {
          "vendor": "n/a",
          "product": "n/a",
          "versions": [
            {
              "status": "affected",
              "version": "n/a"
            }
          ]
        }
      ]
    }
  ],
  "published": "2007-01-09T21:28:00.000",
  "references": [
    {
      "url": "http://bugs.debian.org/cgi-bin/bugreport.cgi/neon26_0.26.2-3_to_mdx1.diff?bug=404723%3Bmsg=5%3Batt=2",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=404723",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://mailman.webdav.org/pipermail/cadaver/2007-January/001015.html",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://mailman.webdav.org/pipermail/neon/2007-January/002362.html",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://osvdb.org/39247",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://secunia.com/advisories/23751",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://secunia.com/advisories/23763",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://secunia.com/advisories/23984",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://www.mandriva.com/security/advisories?name=MDKSA-2007:013",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://www.novell.com/linux/security/advisories/2007_02_sr.html",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://www.securityfocus.com/bid/22035",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://www.vupen.com/english/advisories/2007/0172",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://www.vupen.com/english/advisories/2007/0362",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://www.webdav.org/cadaver/",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://bugs.debian.org/cgi-bin/bugreport.cgi/neon26_0.26.2-3_to_mdx1.diff?bug=404723%3Bmsg=5%3Batt=2",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=404723",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://mailman.webdav.org/pipermail/cadaver/2007-January/001015.html",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://mailman.webdav.org/pipermail/neon/2007-January/002362.html",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://osvdb.org/39247",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://secunia.com/advisories/23751",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://secunia.com/advisories/23763",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://secunia.com/advisories/23984",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.mandriva.com/security/advisories?name=MDKSA-2007:013",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.novell.com/linux/security/advisories/2007_02_sr.html",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.securityfocus.com/bid/22035",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.vupen.com/english/advisories/2007/0172",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.vupen.com/english/advisories/2007/0362",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.webdav.org/cadaver/",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "NVD-CWE-Other"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "Array index error in the uri_lookup function in the URI parser for neon 0.26.0 to 0.26.2, possibly only on 64-bit platforms, allows remote malicious servers to cause a denial of service (crash) via a URI with non-ASCII characters, which triggers a buffer under-read due to a type conversion error that generates a negative index."
    },
    {
      "lang": "es",
      "value": "Error de índice de array en la función uri_lookup del intérprete de URI para neon 0.26.0 hasta 0.26.2, posiblemente sólo en plataformas de 54 bits, permite a servidores remotos maliciosos provocar una denegación de servicio (caída) mediante un URI con caracteres no-ASCII, lo que dispara una lectura de búfer por debajo del límite inferior debido a un error de conversión de tipos que genera un índice negativo."
    }
  ],
  "lastModified": "2026-06-16T22:35:01.477",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:neon:neon:0.26.0:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "6CA5EF13-02E0-414E-8076-9E8CF8791C61"
            },
            {
              "criteria": "cpe:2.3:a:neon:neon:0.26.1:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "D2538986-65F3-4E52-BD74-E31728B14A45"
            },
            {
              "criteria": "cpe:2.3:a:neon:neon:0.26.2:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "D48115F0-4B06-4C4C-8969-7F0518C46257"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "vendorComments": [
    {
      "comment": "Not vulnerable.  This issue does not affect the older versions of neon as shipped with Red Hat Enterprise Linux 2.1, 3, and 4.  This issue also does not affect the older versions of neon included in the cadaver package.",
      "lastModified": "2007-01-15T00:00:00",
      "organization": "Red Hat"
    }
  ],
  "sourceIdentifier": "cve@mitre.org"
}