Bug 223143 - CVE-2006-5876 libsoup Server code crashes upon receiving malformed GET HTTP header
CVE-2006-5876 libsoup Server code crashes upon receiving malformed GET HTTP h...
Product: Red Hat Enterprise Linux 5
Classification: Red Hat
Component: libsoup (Show other bugs)
All Linux
medium Severity medium
: ---
: ---
Assigned To: Matthew Barnes
David Lawrence
: Security
Depends On:
Blocks: CVE-2006-5876
  Show dependency treegraph
Reported: 2007-01-17 18:17 EST by Lubomir Kundrak
Modified: 2007-11-30 17:07 EST (History)
1 user (show)

See Also:
Fixed In Version: RC
Doc Type: Bug Fix
Doc Text:
Story Points: ---
Clone Of:
Last Closed: 2007-02-07 21:18:24 EST
Type: ---
Regression: ---
Mount Type: ---
Documentation: ---
Verified Versions:
Category: ---
oVirt Team: ---
RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: ---

Attachments (Terms of Use)

External Trackers
Tracker ID Priority Status Summary Last Updated
GNOME Desktop 391970 None None None Never

  None (edit)
Description Lubomir Kundrak 2007-01-17 18:17:33 EST
Description of problem:

Programs using libsoup Server code attempts to dereference NULL
pointer upon receival of a header that looks like this:

"GET something\000something\r\n"

Affected code is used just by Rhythmbox's daap plugin in FC{5,6} and RHEL5
Also you can use seahorse from Extras to reproduce the issue

See the debian bugreport for details.

Steps to Reproduce:
1. Run rhythmbox and enable the daap server
2. echo -e "GET abcd\000efgh" |telnet localhost daap
3. Correct the line above, for I haven't tried it :)
Additional info:

Upstream completly rewrote the affected functions. Dunno if debian did
their own patches, but they issued a DSA for that.

Comment 1 Matthew Barnes 2007-01-18 10:51:09 EST
This was fixed in libsoup-2.2.99.  I'll backport the upstream changes.
Comment 2 RHEL Product and Program Management 2007-01-18 11:00:49 EST
This request was evaluated by Red Hat Product Management for inclusion in a Red
Hat Enterprise Linux major release.  Product Management has requested further
review of this request by Red Hat Engineering, for potential inclusion in a Red
Hat Enterprise Linux Major release.  This request is not yet committed for
Comment 3 Matthew Barnes 2007-01-18 12:45:48 EST
Upstream changes applied to libsoup-2.2.98-2.el5.
Comment 4 RHEL Product and Program Management 2007-02-07 21:18:25 EST
A package has been built which should help the problem described in 
this bug report. This report is therefore being closed with a resolution 
of CURRENTRELEASE. You may reopen this bug report if the solution does 
not work for you.

Note You need to log in before you can comment on or make changes to this bug.