Alerts This Week
Warning Icon 1 692
Alerts This Week
Warning Icon 1 692

Fedora 26: Important Advisory for Critical gSOAP DIME Security Fix

fedora
Calendar Grey April 27, 2018
Dist Fedora Esm H88
This software patch resolves a crucial vulnerability in the gSOAP framework concerning the DIME protocol handler, improving overall security.
This patch addresses a critical issue with the DIME protocol receiver that may cause the receiver to become unresponsive when a malformed DIME protocol message is received

Summary

The gSOAP Web services development toolkit offers an XML to C/C++

language binding to ease the development of SOAP/XML Web services in C

and C/C++.

This patch addresses a critical issue with the DIME protocol receiver that may

cause the receiver to become unresponsive when a malformed DIME protocol message

is received. -- https://www.genivia.com/advisory.html

* Wed Apr 18 2018 Mattias Ellert - 2.8.43-3

- Fix issue with DIME protocol receiver and malformed DIME headers

* Tue Aug 1 2017 Mattias Ellert - 2.8.43-2

- CVE-2017-9765

[ 1 ] Bug #1568930 - gsoap: Infinite loop on malformed DIME protocol messages [fedora-all]

https://bugzilla.redhat.com/show_bug.cgi?id=1568930

su -c 'dnf upgrade --advisory FEDORA-2018-a9615e2a1e' at the command

line. For more information, refer to the dnf documentation available at

https://dnf.readthedocs.io/en/latest/command_ref.html

All packages are signed with the Fedora Project GPG key. More details on the

GPG keys used by the Fedora Project can be found at

https://fedoraproject.org/security/

package-announce mailing list -- package-announce@lists.fedoraproject.org

To unsubscribe send an email to package-announce-leave@lists.fedoraproject.org

Change Log

References

Update Instructions

Severity
critical
Lowest
Low
Medium
High
Critical

Product: Fedora 26
Version: 2.8.43
Release: 3.fc26
Summary: Generator Tools for Coding SOAP/XML Web Services in C and C++

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here