Heap-based buffer overflow in the nerfc1036parse date parsing function for the neon library (libneon) 0.24.5 and earlier, as used by cadaver before 0.22, allows remote WebDAV servers to execute arbitrary code on the client.
{ "urgency": "not yet assigned" }