CVE-2009-2474 by Fred · 21/08/2009 neon before 0.28.6, when OpenSSL or GnuTLS is used, does not properly handle a ‘