Oval Definition:oval:com.redhat.rhsa:def:20090344
Revision Date:2009-03-16Version:637
Title:RHSA-2009:0344: libsoup security update (Moderate)
Description:libsoup is an HTTP client/library implementation for GNOME written in C. It was originally part of a SOAP (Simple Object Access Protocol) implementation called Soup, but the SOAP and non-SOAP parts have now been split into separate packages.

  • An integer overflow flaw which caused a heap-based buffer overflow was discovered in libsoup's Base64 encoding routine. An attacker could use this flaw to crash, or, possibly, execute arbitrary code. This arbitrary code would execute with the privileges of the application using libsoup's Base64 routine to encode large, untrusted inputs. (CVE-2009-0585)

    All users of libsoup and evolution28-libsoup should upgrade to these updated packages, which contain a backported patch to resolve this issue. All running applications using the affected library function (such as Evolution configured to connect to the GroupWise back-end) must be restarted for the update to take effect.
  • Family:unixClass:patch
    Status:Reference(s):CVE-2009-0585
    RHSA-2009:0344
    RHSA-2009:0344-01
    RHSA-2009:0344-01
    Platform(s):Red Hat Enterprise Linux 4
    Red Hat Enterprise Linux 5
    Product(s):
    Definition Synopsis
  • Red Hat Enterprise Linux must be installed
  • OR Package Information
  • Red Hat Enterprise Linux 4 is installed
  • AND
  • libsoup is earlier than 0:2.2.1-4.el4.1
  • AND libsoup is signed with Red Hat redhatrelease2 key
  • libsoup-devel is earlier than 0:2.2.1-4.el4.1
  • AND libsoup-devel is signed with Red Hat redhatrelease2 key
  • evolution28-libsoup is earlier than 0:2.2.98-5.el4.1
  • AND evolution28-libsoup is signed with Red Hat redhatrelease2 key
  • evolution28-libsoup-devel is earlier than 0:2.2.98-5.el4.1
  • AND evolution28-libsoup-devel is signed with Red Hat redhatrelease2 key
  • OR Package Information
  • Red Hat Enterprise Linux 5 is installed
  • AND
  • libsoup is earlier than 0:2.2.98-2.el5_3.1
  • AND libsoup is signed with Red Hat redhatrelease2 key
  • libsoup-devel is earlier than 0:2.2.98-2.el5_3.1
  • AND libsoup-devel is signed with Red Hat redhatrelease2 key
  • BACK