Debian: New libsoup packages fix denial of service

    Date12 Jan 2007
    CategoryDebian
    2812
    Posted ByLinuxSecurity Advisories
    Roland Lezuo and Josselin Mouette discovered that the libsoup HTTP library performs insufficient sanitising when parsing HTTP headers, which might lead to denial of service.
    - --------------------------------------------------------------------------
    Debian Security Advisory DSA 1248-1                    This email address is being protected from spambots. You need JavaScript enabled to view it.
    http://www.debian.org/security/                         Moritz Muehlenhoff
    January 12nd, 2007                      http://www.debian.org/security/faq
    - --------------------------------------------------------------------------
    
    Package        : libsoup
    Vulnerability  : missing input sanitising
    Problem-Type   : remote
    Debian-specific: no
    CVE ID         : CVE-2006-5876
    Debian Bug     : 405197
    
    Roland Lezuo and Josselin Mouette discovered that the libsoup HTTP
    library performs insufficient sanitising when parsing HTTP headers,
    which might lead to denial of service.
    
    For the stable distribution (sarge) this problem has been fixed in
    version 2.2.3-2sarge1.
    
    For the upcoming stable distribution (etch) this problem has been
    fixed in version 2.2.98-2.
    
    For the unstable distribution (sid) this problem has been fixed in
    version 2.2.98-2.
    
    We recommend that you upgrade your libsoup package.
    
    
    Upgrade Instructions
    - --------------------
    
    wget url
            will fetch the file for you
    dpkg -i file.deb
            will install the referenced file.
    
    If you are using the apt-get package manager, use the line for
    sources.list as given below:
    
    apt-get update
            will update the internal database
    apt-get upgrade
            will install corrected packages
    
    You may use an automated update by adding the resources from the
    footer to the proper configuration.
    
    
    Debian GNU/Linux 3.1 alias sarge
    - --------------------------------
    
      Source archives:
    
        http://security.debian.org/pool/updates/main/libs/libsoup/libsoup_2.2.3-2sarge1.dsc
          Size/MD5 checksum:      679 adbad6fcde3be4be01c8eac2da55c712
        http://security.debian.org/pool/updates/main/libs/libsoup/libsoup_2.2.3-2sarge1.diff.gz
          Size/MD5 checksum:    77637 62b8b84a032e79802788ac8fad2a8b1a
        http://security.debian.org/pool/updates/main/libs/libsoup/libsoup_2.2.3.orig.tar.gz
          Size/MD5 checksum:   479599 1c3e8c05a702340f9170d30a370a7344
    
      Architecture independent components:
    
        http://security.debian.org/pool/updates/main/libs/libsoup/libsoup2.2-doc_2.2.3-2sarge1_all.deb
          Size/MD5 checksum:    89712 28de5acce82f292d53488316d4d21f47
    
      Alpha architecture:
    
        http://security.debian.org/pool/updates/main/libs/libsoup/libsoup2.2-7_2.2.3-2sarge1_alpha.deb
          Size/MD5 checksum:   121006 63acdee0902aef63cd9de5234ba4c75f
        http://security.debian.org/pool/updates/main/libs/libsoup/libsoup2.2-dev_2.2.3-2sarge1_alpha.deb
          Size/MD5 checksum:   179700 cae14f17a787681ffd64af595df4320a
    
      AMD64 architecture:
    
        http://security.debian.org/pool/updates/main/libs/libsoup/libsoup2.2-7_2.2.3-2sarge1_amd64.deb
          Size/MD5 checksum:   109672 d36f765bcd4bf336f9dfd3efa93aca01
        http://security.debian.org/pool/updates/main/libs/libsoup/libsoup2.2-dev_2.2.3-2sarge1_amd64.deb
          Size/MD5 checksum:   137628 48e8ae141d696f82c38a8e4464da7624
    
      ARM architecture:
    
        http://security.debian.org/pool/updates/main/libs/libsoup/libsoup2.2-7_2.2.3-2sarge1_arm.deb
          Size/MD5 checksum:   100968 2a51612277c7fb122d7244729bdabc3c
        http://security.debian.org/pool/updates/main/libs/libsoup/libsoup2.2-dev_2.2.3-2sarge1_arm.deb
          Size/MD5 checksum:   134098 213cfe1f767b22eb8baedaf7dae4e705
    
      HP Precision architecture:
    
        http://security.debian.org/pool/updates/main/libs/libsoup/libsoup2.2-7_2.2.3-2sarge1_hppa.deb
          Size/MD5 checksum:   118582 4a28fbaff712a41026027e46477b2db4
        http://security.debian.org/pool/updates/main/libs/libsoup/libsoup2.2-dev_2.2.3-2sarge1_hppa.deb
          Size/MD5 checksum:   150680 0a5331f409f1255a7afe2136a7b75efa
    
      Intel IA-32 architecture:
    
        http://security.debian.org/pool/updates/main/libs/libsoup/libsoup2.2-7_2.2.3-2sarge1_i386.deb
          Size/MD5 checksum:   103256 cc59e5bfe0236843a9f035e21084472e
        http://security.debian.org/pool/updates/main/libs/libsoup/libsoup2.2-dev_2.2.3-2sarge1_i386.deb
          Size/MD5 checksum:   124718 1a9f5949d15ee315df06dd7d4f030bad
    
      Intel IA-64 architecture:
    
        http://security.debian.org/pool/updates/main/libs/libsoup/libsoup2.2-7_2.2.3-2sarge1_ia64.deb
          Size/MD5 checksum:   137120 3036044195764214e74f6e94e557f373
        http://security.debian.org/pool/updates/main/libs/libsoup/libsoup2.2-dev_2.2.3-2sarge1_ia64.deb
          Size/MD5 checksum:   180256 48c1f4958dd773f963228874cf3b0493
    
      Motorola 680x0 architecture:
    
        http://security.debian.org/pool/updates/main/libs/libsoup/libsoup2.2-7_2.2.3-2sarge1_m68k.deb
          Size/MD5 checksum:   104094 ca8ef51bd4f5622530fb246818b9bd38
        http://security.debian.org/pool/updates/main/libs/libsoup/libsoup2.2-dev_2.2.3-2sarge1_m68k.deb
          Size/MD5 checksum:   119564 1400d2fdaa1416454a4bd1a6260064d4
    
      Big endian MIPS architecture:
    
        http://security.debian.org/pool/updates/main/libs/libsoup/libsoup2.2-7_2.2.3-2sarge1_mips.deb
          Size/MD5 checksum:   102578 5cc6cb77f78a633b718111b01cd1ac56
        http://security.debian.org/pool/updates/main/libs/libsoup/libsoup2.2-dev_2.2.3-2sarge1_mips.deb
          Size/MD5 checksum:   145276 89f3fbf38a9a3a6c23d2c7c403a25e35
    
      Little endian MIPS architecture:
    
        http://security.debian.org/pool/updates/main/libs/libsoup/libsoup2.2-7_2.2.3-2sarge1_mipsel.deb
          Size/MD5 checksum:   102560 5f8c1dc2888c63b5fb7cbc7e765227a1
        http://security.debian.org/pool/updates/main/libs/libsoup/libsoup2.2-dev_2.2.3-2sarge1_mipsel.deb
          Size/MD5 checksum:   145232 1ab42e08c45e37a8c42db91eb0d05582
    
      PowerPC architecture:
    
        http://security.debian.org/pool/updates/main/libs/libsoup/libsoup2.2-7_2.2.3-2sarge1_powerpc.deb
          Size/MD5 checksum:   106390 57dc0f86443250f7160202c3514f8e5e
        http://security.debian.org/pool/updates/main/libs/libsoup/libsoup2.2-dev_2.2.3-2sarge1_powerpc.deb
          Size/MD5 checksum:   139376 25103bd1d805b97fc9d524602afce1ea
    
      IBM S/390 architecture:
    
        http://security.debian.org/pool/updates/main/libs/libsoup/libsoup2.2-7_2.2.3-2sarge1_s390.deb
          Size/MD5 checksum:   115614 2e5422ec386daf008dd8d8c8af725366
        http://security.debian.org/pool/updates/main/libs/libsoup/libsoup2.2-dev_2.2.3-2sarge1_s390.deb
          Size/MD5 checksum:   138072 2d692116c7e50dde248f58b85d9ebdfd
    
      Sun Sparc architecture:
    
        http://security.debian.org/pool/updates/main/libs/libsoup/libsoup2.2-7_2.2.3-2sarge1_sparc.deb
          Size/MD5 checksum:   105966 da20be0e50755c15ead7dca8a7327ecc
        http://security.debian.org/pool/updates/main/libs/libsoup/libsoup2.2-dev_2.2.3-2sarge1_sparc.deb
          Size/MD5 checksum:   131482 2622023dd2bc6508aeb6a200ba904260
    
    
      These files will probably be moved into the stable distribution on
      its next update.
    
    - ---------------------------------------------------------------------------------
    For apt-get: deb http://security.debian.org/ stable/updates main
    For dpkg-ftp: ftp://security.debian.org/debian-security dists/stable/updates/main
    Mailing list: This email address is being protected from spambots. You need JavaScript enabled to view it.
    
    You are not authorised to post comments.

    Comments powered by CComment

    LinuxSecurity Poll

    What do you think of the articles on LinuxSecurity?

    No answer selected. Please try again.
    Please select either existing option or enter your own, however not both.
    Please select minimum 0 answer(s) and maximum 3 answer(s).
    /main-polls/24-what-do-you-think-of-the-quality-of-the-articles-on-linuxsecurity?task=poll.vote&format=json
    24
    radio
    [{"id":"87","title":"Excellent, don't change a thing!","votes":"39","type":"x","order":"1","pct":50,"resources":[]},{"id":"88","title":"Should be more technical","votes":"11","type":"x","order":"2","pct":14.1,"resources":[]},{"id":"89","title":"Should include more HOWTOs","votes":"28","type":"x","order":"3","pct":35.9,"resources":[]}]["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"]["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"]350
    bottom200

    We use cookies to provide and improve our services. By using our site, you consent to our Cookie Policy.