|
|
| |
|
| |
libsoup: arbitrary code execution
| Package(s): | libsoup |
CVE #(s): | CVE-2009-0585
|
| Created: | March 16, 2009 |
Updated: | May 13, 2009 |
| Description: |
From the Red Hat advisory:
An integer overflow flaw which caused a heap-based buffer overflow was
discovered in libsoup's Base64 encoding routine. An attacker could use this
flaw to crash, or, possibly, execute arbitrary code. This arbitrary code
would execute with the privileges of the application using libsoup's Base64
routine to encode large, untrusted inputs. (CVE-2009-0585)
|
| Alerts: |
|
( Log in to post comments)
|
|
|