Bug 223144 (CVE-2006-5876)
Summary: | CVE-2006-5876 libsoup Server code crashes upon receiving malformed GET HTTP header | ||
---|---|---|---|
Product: | [Fedora] Fedora | Reporter: | Lubomir Kundrak <lkundrak> |
Component: | libsoup | Assignee: | Matthew Barnes <mbarnes> |
Status: | CLOSED CURRENTRELEASE | QA Contact: | |
Severity: | medium | Docs Contact: | |
Priority: | medium | ||
Version: | 6 | CC: | alexl |
Target Milestone: | --- | Keywords: | Reopened, Security |
Target Release: | --- | ||
Hardware: | All | ||
OS: | Linux | ||
URL: | http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=405197 | ||
Whiteboard: | impact=moderate,source=debian,reported=20070116,public=20071111 | ||
Fixed In Version: | libsoup-2.2.99-1.fc6 | Doc Type: | Bug Fix |
Doc Text: | Story Points: | --- | |
Clone Of: | Environment: | ||
Last Closed: | 2007-02-19 17:23:01 UTC | Type: | --- |
Regression: | --- | Mount Type: | --- |
Documentation: | --- | CRM: | |
Verified Versions: | Category: | --- | |
oVirt Team: | --- | RHEL 7.3 requirements from Atomic Host: | |
Cloudforms Team: | --- | Target Upstream Version: | |
Embargoed: | |||
Bug Depends On: | 223143 | ||
Bug Blocks: |
Description
Lubomir Kundrak
2007-01-17 23:27:16 UTC
This has been fixed in libsoup-2.2.99. Fedora Core 6 currently has 2.2.98. I'll address this by pushing 2.2.99 as a Fedora Core 6 update. libsoup-2.2.99-1.fc6 has been pushed for fc6, which should resolve this issue. If these problems are still present in this version, then please make note of it in this bug report. libsoup-2.2.99-1.fc6 has been pushed for fc6, which should resolve this issue. If these problems are still present in this version, then please make note of it in this bug report. Closing as CURRENTRELEASE. I'm reopening this ticket as there has not yet been a FC5 update for libsoup (we'll use this one bug to track both as it's a bit easier). libsoup-2.2.96-2.fc5 has been pushed for fc5, which should resolve this issue. If these problems are still present in this version, then please make note of it in this bug report. Closing as CURRENTRELEASE. |