Alerts This Week
Warning Icon 1 916
Alerts This Week
Warning Icon 1 916

Fedora Core 6: 2007-109 Critical: Libsoup HTTP Header Crash

fedora
Calendar Grey January 29, 2007
Dist Fedora Esm H88
Attention Users: libsoup 2.2.99-1.fc6 update resolves critical vulnerabilities causing server instability due to improperly formatted HTTP GET requests.
Update to the latest libsoup 2.2 release. This release fixes a security flaw that causes the libsoup server to crash when it receives a malformed HTTP GET header.

Summary

Libsoup is an HTTP library implementation in C. It was originally part

of a SOAP (Simple Object Access Protocol) implementation called Soup, but

the SOAP and non-SOAP parts have now been split into separate packages.

libsoup uses the Glib main loop and is designed to work well with GTK

applications. This enables GNOME applications to access HTTP servers

on the network in a completely asynchronous fashion, very similar to

the Gtk+ programming model (a synchronous operation mode is also

supported for those who want it).

Update to the latest libsoup 2.2 release.

This release fixes a security flaw that causes the libsoup

server to crash when it receives a malformed HTTP GET header.

- Update to 2.2.99

0292f492c61347dca39abc1c7421769fab342e99 SRPMS/libsoup-2.2.99-1.fc6.src.rpm

0292f492c61347dca39abc1c7421769fab342e99 noarch/libsoup-2.2.99-1.fc6.src.rpm

18fcdcd35970e1ab685bfdf6afa32489b1716d27 ppc/debug/libsoup-debuginfo-2.2.99-1.fc6.ppc.rpm

56063cbe73f6285a9eb7c2a765fb8fd71c1620e6 ppc/libsoup-devel-2.2.99-1.fc6.ppc.rpm

a8bfbf47d8954856debc33b9a757cd50f79cd69e ppc/libsoup-2.2.99-1.fc6.ppc.rpm

6d2f5352a739d11a29e8da1c1b25d543526c14bc x86_64/debug/libsoup-debuginfo-2.2.99-1.fc6.x86_64.rpm

1fb2eec4951fc3fd446ddce4ff127da5effaec9d x86_64/libsoup-2.2.99-1.fc6.x86_64.rpm

9b29f9df2eead6490c38ae483b613506f8b90969 x86_64/libsoup-devel-2.2.99-1.fc6.x86_64.rpm

47eddf389e40d23e152f62ade508e725fc457b94 i386/libsoup-devel-2.2.99-1.fc6.i386.rpm

4f82391dbb51da98dabe68ac28e4e9e87c22fc5f i386/libsoup-2.2.99-1.fc6.i386.rpm

13fd5c05b2370afc8df214ff8cbd4b54ef4d634f i386/debug/libsoup-debuginfo-2.2.99-1.fc6.i386.rpm

This update can be installed with the 'yum' update program. Use 'yum update

package-name' at the command line. For more information, refer to 'Managing

Software with yum,' available at .

Fedora-package-announce mailing list

Fedora-package-announce@redhat.com

https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/

Change Log

References

Update Instructions

Severity
critical
Lowest
Low
Medium
High
Critical

Name: libsoup
Version: 2.2.99
Release: 1.fc6
Summary: Soup, an HTTP library implementation

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here