Multiple vulnerabilities have been fixed in the gSOAP toolkit for developing Web services. CVE-2020-13574 . - ------------------------------------------------------------------------- Debian LTS Advisory DLA-3745-1
A denial-of-service vulnerability exists in the WS-Security plugin functionality of Genivia gSOAP 2.8.107. A specially crafted SOAP request can lead to denial of service. An attacker can send an HTTP request to trigger this vulnerability (CVE-2020-13574). . MGASA-2021-0263 - Updated gsoap packages fix security vulnerabilities Publication date: 16 Jun 2021 URL: https://advisories.mageia.org/MGASA-2021-0263.html Type: security Affected Mageia releases: 7, 8 CVE: CVE-2020-13574, CVE-2020-13575, CVE-2020-13576, CVE-2020-13577, CVE-2020-13578 A denial-of-service vulnerability exists in the WS-Security plugin functionality of Genivia gSOAP 2.8.107. A specially crafted SOAP request can lead to denial of service. An attacker can send an HTTP request to trigger this vulnerability (CVE-2020-13574). A denial-of-service vulnerability exists in the WS-Addressing plugin functionality of Genivia gSOAP 2.8.107. A specially crafted SOAP request can lead to denial of service. An attacker can send an HTTP request to trigger this vulnerability (CVE-2020-13575). A code execution vulnerability exists in the WS-Addressing plugin functionality of Genivia gSOAP 2.8.107. A specially crafted SOAP request can lead to remote code execution. An attacker can send an HTTP request to trigger this vulnerability (CVE-2020-13576). A denial-of-service vulnerability exists in the WS-Security plugin functionality of Genivia gSOAP 2.8.107. A specially crafted SOAP request can lead to denial of service. An attacker can send an HTTP request to trigger this vulnerability (CVE-2020-13577). A denial-of-service vulnerability exists in the WS-Security plugin functionality of Genivia gSOAP 2.8.107. A specially crafted SOAP request can lead to denial of service. An attacker can send an HTTP request to trigger this vulnerability (CVE-2020-13578). References: - https://bugs.mageia.org/show_bug.cgi?id=29015 - https://www.cve.org/CVERecord?id=CVE-2020-13574 - https://www.cve.org/CVERecord?id=CVE-2020-13575 -https://www.cve.org/CVERecord?id=CVE-2020-13576 - https://www.cve.org/CVERecord?id=CVE-2020-13577 - https://www.cve.org/CVERecord?id=CVE-2020-13578 - https://lists.fedoraproject.org/archives/list/
An update that fixes one vulnerability is now available. . openSUSE Security Update: Security update for gsoap ______________________________________________________________________________ Announcement ID: openSUSE-SU-2021:0664-1 Rating: important References: #1182098 Cross-References: CVE-2020-13576 CVSS scores: CVE-2020-13576 (NVD) : 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H Affected Products: openSUSE Backports SLE-15-SP2 ______________________________________________________________________________ An update that fixes one vulnerability is now available. Description: This update for gsoap fixes the following issues: - CVE-2020-13576: Fixed a remote code execution via specially crafted SOAP request inside the WS-Addressing plugin (boo#1182098) This update was imported from the openSUSE:Leap:15.2:Update update project. Patch Instructions: To install this openSUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - openSUSE Backports SLE-15-SP2: zypper in -t patch openSUSE-2021-664=1 Package List: - openSUSE Backports SLE-15-SP2 (aarch64 ppc64le s390x x86_64): gsoap-devel-2.8.102-bp152.2.4.1 libgsoap-2_8_102-2.8.102-bp152.2.4.1 - openSUSE Backports SLE-15-SP2 (noarch): gsoap-doc-2.8.102-bp152.2.4.1 References: https://www.suse.com/security/cve/CVE-2020-13576.html https://bugzilla.suse.com/1182098 . This software patch for gsoap resolves a significant remote exploitation vulnerability in openSUSE Backports.. openSUSE Security,gsoap Update,Critical Flaw Fix,Remote Code Execution. . Severity: Important. LinuxSecurity.com Team
An update that fixes one vulnerability is now available. . openSUSE Security Update: Security update for gsoap ______________________________________________________________________________ Announcement ID: openSUSE-SU-2021:0632-1 Rating: important References: #1182098 Cross-References: CVE-2020-13576 CVSS scores: CVE-2020-13576 (NVD) : 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H Affected Products: openSUSE Leap 15.2 ______________________________________________________________________________ An update that fixes one vulnerability is now available. Description: This update for gsoap fixes the following issues: - CVE-2020-13576: Fixed a remote code execution via specially crafted SOAP request inside the WS-Addressing plugin (boo#1182098) Patch Instructions: To install this openSUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - openSUSE Leap 15.2: zypper in -t patch openSUSE-2021-632=1 Package List: - openSUSE Leap 15.2 (x86_64): gsoap-debuginfo-2.8.102-lp152.2.3.1 gsoap-debugsource-2.8.102-lp152.2.3.1 gsoap-devel-2.8.102-lp152.2.3.1 gsoap-devel-debuginfo-2.8.102-lp152.2.3.1 libgsoap-2_8_102-2.8.102-lp152.2.3.1 libgsoap-2_8_102-debuginfo-2.8.102-lp152.2.3.1 - openSUSE Leap 15.2 (noarch): gsoap-doc-2.8.102-lp152.2.3.1 References: https://www.suse.com/security/cve/CVE-2020-13576.html https://bugzilla.suse.com/1182098 . A vital security patch for gsoap on openSUSE addresses a remote code execution flaw recognized as CVE-2020-13576.. openSUSE Security,gsoap Remote Code Execution,Software Update. . Severity: Important. LinuxSecurity.com Team
Backporting upstream fixes - Fixes CVE: CVE-2020-13574 CVE-2020-13575 CVE-2020-13577 CVE-2020-13578 - Fixes CVE: CVE-2020-13576. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2021-1da151722e 2021-03-19 19:51:22.366602 --------------------------------------------------------------------------------Name : gsoap Product : Fedora 34 Version : 2.8.104 Release : 4.fc34 URL : https://www.genivia.com/dev.html Summary : Generator Tools for Coding SOAP/XML Web Services in C and C++ Description : The gSOAP Web services development toolkit offers an XML to C/C++ language binding to ease the development of SOAP/XML Web services in C and C/C++. --------------------------------------------------------------------------------Update Information: Backporting upstream fixes - Fixes CVE: CVE-2020-13574 CVE-2020-13575 CVE-2020-13577 CVE-2020-13578 - Fixes CVE: CVE-2020-13576 --------------------------------------------------------------------------------ChangeLog: * Mon Mar 8 2021 Mattias Ellert - 2.8.104-4 - Backporting upstream fixes - Fixes CVE: CVE-2020-13574 CVE-2020-13575 CVE-2020-13577 CVE-2020-13578 - Fixes CVE: CVE-2020-13576 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2021-1da151722e' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ --------------------------------------------------------------------------------_______________________________________________ package-announce mailing list --
Backporting upstream fixes - Fixes CVE: CVE-2020-13574 CVE-2020-13575 CVE-2020-13577 CVE-2020-13578 - Fixes CVE: CVE-2020-13576. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2021-faea36a9c3 2021-03-17 02:17:03.380896 --------------------------------------------------------------------------------Name : gsoap Product : Fedora 33 Version : 2.8.104 Release : 4.fc33 URL : https://www.genivia.com/dev.html Summary : Generator Tools for Coding SOAP/XML Web Services in C and C++ Description : The gSOAP Web services development toolkit offers an XML to C/C++ language binding to ease the development of SOAP/XML Web services in C and C/C++. --------------------------------------------------------------------------------Update Information: Backporting upstream fixes - Fixes CVE: CVE-2020-13574 CVE-2020-13575 CVE-2020-13577 CVE-2020-13578 - Fixes CVE: CVE-2020-13576 --------------------------------------------------------------------------------ChangeLog: * Mon Mar 8 2021 Mattias Ellert - 2.8.104-4 - Backporting upstream fixes - Fixes CVE: CVE-2020-13574 CVE-2020-13575 CVE-2020-13577 CVE-2020-13578 - Fixes CVE: CVE-2020-13576 * Tue Jan 26 2021 Fedora Release Engineering - 2.8.104-3 - Rebuilt for https://fedoraproject.org/wiki/Fedora_34_Mass_Rebuild --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2021-faea36a9c3' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be foundat https://fedoraproject.org/security/ --------------------------------------------------------------------------------_______________________________________________ package-announce mailing list --
This patch addresses a critical issue with the DIME protocol receiver that may cause the receiver to become unresponsive when a malformed DIME protocol message is received. -- https://www.genivia.com/advisory.html. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2018-b7a613ea5d 2018-04-27 23:35:59.891088 --------------------------------------------------------------------------------Name : gsoap Product : Fedora 27 Version : 2.8.49 Release : 4.fc27 URL : https://www.genivia.com/dev.html Summary : Generator Tools for Coding SOAP/XML Web Services in C and C++ Description : The gSOAP Web services development toolkit offers an XML to C/C++ language binding to ease the development of SOAP/XML Web services in C and C/C++. --------------------------------------------------------------------------------Update Information: This patch addresses a critical issue with the DIME protocol receiver that may cause the receiver to become unresponsive when a malformed DIME protocol message is received. -- https://www.genivia.com/advisory.html --------------------------------------------------------------------------------ChangeLog: * Wed Apr 18 2018 Mattias Ellert - 2.8.49-4 - Fix issue with DIME protocol receiver and malformed DIME headers --------------------------------------------------------------------------------References: [ 1 ] Bug #1568930 - gsoap: Infinite loop on malformed DIME protocol messages [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=1568930 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2018-b7a613ea5d' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPGkeys used by the Fedora Project can be found at https://fedoraproject.org/security/ -------------------------------------------------------------------------------- _______________________________________________ package-announce mailing list --
This patch addresses a critical issue with the DIME protocol receiver that may cause the receiver to become unresponsive when a malformed DIME protocol message is received. -- https://www.genivia.com/advisory.html. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2018-b7a613ea5d 2018-04-27 23:35:59.891088 --------------------------------------------------------------------------------Name : gsoap Product : Fedora 27 Version : 2.8.49 Release : 4.fc27 URL : https://www.genivia.com/dev.html Summary : Generator Tools for Coding SOAP/XML Web Services in C and C++ Description : The gSOAP Web services development toolkit offers an XML to C/C++ language binding to ease the development of SOAP/XML Web services in C and C/C++. --------------------------------------------------------------------------------Update Information: This patch addresses a critical issue with the DIME protocol receiver that may cause the receiver to become unresponsive when a malformed DIME protocol message is received. -- https://www.genivia.com/advisory.html --------------------------------------------------------------------------------ChangeLog: * Wed Apr 18 2018 Mattias Ellert - 2.8.49-4 - Fix issue with DIME protocol receiver and malformed DIME headers --------------------------------------------------------------------------------References: [ 1 ] Bug #1568930 - gsoap: Infinite loop on malformed DIME protocol messages [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=1568930 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2018-b7a613ea5d' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPGkeys used by the Fedora Project can be found at https://fedoraproject.org/security/ -------------------------------------------------------------------------------- _______________________________________________ package-announce mailing list --
Get the latest Linux and open source security news straight to your inbox.