RHSA-2009:0344-01 -- Redhat libsoup and evolution28-libsoup
|ID: oval:org.secpod.oval:def:500525||Date: (C)2012-01-31 (M)2017-10-04|
|Class: PATCH||Family: unix|
libsoup is an HTTP client/library implementation for GNOME written in C. It was originally part of a SOAP implementation called Soup, but the SOAP and non-SOAP parts have now been split into separate packages. An integer overflow flaw which caused a heap-based buffer overflow was discovered in libsoup"s Base64 encoding routine. An attacker could use this flaw to crash, or, possibly, execute arbitrary code. This arbitrary code would execute with the privileges of the application using libsoup"s Base64 routine to encode large, untrusted inputs. All users of libsoup and evolution28-libsoup should upgrade to these updated packages, which contain a backported patch to resolve this issue. All running applications using the affected library function must be restarted for the update to take effect.
|Red Hat Enterprise Linux 5|
|Red Hat Enterprise Linux 4|