[Forgot Password]
Login  Register Subscribe

30430

 
 

423868

 
 

247862

 
 

909

 
 

194603

 
 

282

Paid content will be excluded from the download.


Download | Alert*
OVAL

RHSA-2009:0344-01 -- Redhat libsoup and evolution28-libsoup

ID: oval:org.secpod.oval:def:500525Date: (C)2012-01-31   (M)2023-02-20
Class: PATCHFamily: unix




libsoup is an HTTP client/library implementation for GNOME written in C. It was originally part of a SOAP implementation called Soup, but the SOAP and non-SOAP parts have now been split into separate packages. An integer overflow flaw which caused a heap-based buffer overflow was discovered in libsoup"s Base64 encoding routine. An attacker could use this flaw to crash, or, possibly, execute arbitrary code. This arbitrary code would execute with the privileges of the application using libsoup"s Base64 routine to encode large, untrusted inputs. All users of libsoup and evolution28-libsoup should upgrade to these updated packages, which contain a backported patch to resolve this issue. All running applications using the affected library function must be restarted for the update to take effect.

Platform:
Red Hat Enterprise Linux 5
Red Hat Enterprise Linux 4
Product:
libsoup
evolution28-libsoup
Reference:
RHSA-2009:0344-01
CVE-2009-0585
CVE    1
CVE-2009-0585
CPE    4
cpe:/o:redhat:enterprise_linux:5
cpe:/o:redhat:enterprise_linux:4
cpe:/a:gnome:evolution28-libsoup
cpe:/a:libsoup:libsoup
...

© SecPod Technologies