LWN.net Logo

libsoup: arbitrary code execution

Package(s):libsoup CVE #(s):CVE-2009-0585
Created:March 16, 2009 Updated:May 13, 2009
Description:

From the Red Hat advisory:

An integer overflow flaw which caused a heap-based buffer overflow was discovered in libsoup's Base64 encoding routine. An attacker could use this flaw to crash, or, possibly, execute arbitrary code. This arbitrary code would execute with the privileges of the application using libsoup's Base64 routine to encode large, untrusted inputs. (CVE-2009-0585)

Alerts:
SuSE SUSE-SR:2009:010 2009-05-12
Mandriva MDVSA-2009:081 2009-03-27
Debian DSA-1748-1 2009-03-20
CentOS CESA-2009:0344 2009-03-17
Ubuntu USN-737-1 2009-03-16
Red Hat RHSA-2009:0344-01 2009-03-16

(Log in to post comments)

Copyright © 2012, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds