Vulnerability Name:

CVE-2006-5876 (CCN-31519)

Assigned:2006-11-14
Published:2007-01-12
Updated:2017-07-20
Summary:The soup_headers_parse function in soup-headers.c for libsoup HTTP library before 2.2.99 allows remote attackers to cause a denial of service (crash) via malformed HTTP headers, probably involving missing fields or values.
CVSS v3 Severity:5.3 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L)
Exploitability Metrics:Attack Vector (AV): Network
Attack Complexity (AC): Low
Privileges Required (PR): None
User Interaction (UI): None
Scope:Scope (S): Unchanged
Impact Metrics:Confidentiality (C): None
Integrity (I): None
Availibility (A): Low
CVSS v2 Severity:7.8 High (CVSS v2 Vector: AV:N/AC:L/Au:N/C:N/I:N/A:C)
5.8 Medium (Temporal CVSS v2 Vector: AV:N/AC:L/Au:N/C:N/I:N/A:C/E:U/RL:OF/RC:C)
Exploitability Metrics:Access Vector (AV): Network
Access Complexity (AC): Low
Authentication (Au): None
Impact Metrics:Confidentiality (C): None
Integrity (I): None
Availibility (A): Complete
5.0 Medium (CCN CVSS v2 Vector: AV:N/AC:L/Au:N/C:N/I:N/A:P)
3.7 Low (CCN Temporal CVSS v2 Vector: AV:N/AC:L/Au:N/C:N/I:N/A:P/E:U/RL:OF/RC:C)
Exploitability Metrics:Access Vector (AV): Network
Access Complexity (AC): Low
Athentication (Au): None
Impact Metrics:Confidentiality (C): None
Integrity (I): None
Availibility (A): Partial
Vulnerability Type:CWE-Other
Vulnerability Consequences:Denial of Service
References:Source: MITRE
Type: CNA
CVE-2006-5876

Source: FEDORA
Type: UNKNOWN
FEDORA-2007-109

Source: CONFIRM
Type: UNKNOWN
http://ftp.gnome.org/pub/gnome/sources/libsoup/2.2/libsoup-2.2.99.news

Source: CCN
Type: libsoup Web site
LibSoup - GNOME Live!

Source: OSVDB
Type: UNKNOWN
31667

Source: CCN
Type: SA23734
libsoup "soup_headers_parse()" Denial of Service

Source: SECUNIA
Type: UNKNOWN
23734

Source: SECUNIA
Type: UNKNOWN
23770

Source: SECUNIA
Type: UNKNOWN
23871

Source: SECUNIA
Type: UNKNOWN
23873

Source: SECUNIA
Type: UNKNOWN
23961

Source: SECUNIA
Type: UNKNOWN
23976

Source: DEBIAN
Type: UNKNOWN
DSA-1248

Source: DEBIAN
Type: DSA-1248
libsoup -- missing input sanitising

Source: MANDRIVA
Type: UNKNOWN
MDKSA-2007:029

Source: CCN
Type: OSVDB ID: 31667
libsoup soup_headers_parse DoS

Source: BID
Type: UNKNOWN
22034

Source: CCN
Type: BID-22034
LibSoup Library HTTP Headers Remote Denial of Service Vulnerability

Source: CCN
Type: USN-411-1
libsoup vulnerability

Source: UBUNTU
Type: UNKNOWN
USN-411-1

Source: VUPEN
Type: UNKNOWN
ADV-2007-0173

Source: XF
Type: UNKNOWN
libsoup-soupheadersparse-dos(31519)

Source: XF
Type: UNKNOWN
libsoup-soupheadersparse-dos(31519)

Source: CONFIRM
Type: UNKNOWN
https://issues.rpath.com/browse/RPL-965

Vulnerable Configuration:Configuration 1:
  • cpe:/a:libsoup:libsoup:2.2.98:*:*:*:*:*:*:*

  • * Denotes that component is vulnerable
    Oval Definitions
    Definition IDClassTitleLast Modified
    oval:org.opensuse.security:def:20065876
    V
    CVE-2006-5876
    2022-06-30
    oval:org.opensuse.security:def:42381
    P
    Security update for the Linux Kernel (Important)
    2022-05-16
    oval:org.opensuse.security:def:42177
    P
    Security update for dnsmasq (Important)
    2022-04-22
    oval:org.opensuse.security:def:112840
    P
    libsoup-2_4-1-2.72.0-2.5 on GA media (Moderate)
    2022-01-17
    oval:org.opensuse.security:def:31751
    P
    Security update for java-1_8_0-ibm (Important) (in QA)
    2022-01-04
    oval:org.opensuse.security:def:32217
    P
    Security update for samba (Important)
    2021-11-19
    oval:org.opensuse.security:def:31697
    P
    Security update for opensc (Important)
    2021-10-29
    oval:org.opensuse.security:def:26154
    P
    Security update for ncurses (Moderate)
    2021-10-20
    oval:org.opensuse.security:def:31290
    P
    Security update for the Linux Kernel (Live Patch 38 for SLE 12 SP3) (Important)
    2021-10-18
    oval:org.opensuse.security:def:31691
    P
    Security update for apache2 (Important)
    2021-10-06
    oval:org.opensuse.security:def:106304
    P
    libsoup-2_4-1-2.72.0-2.5 on GA media (Moderate)
    2021-10-01
    oval:org.opensuse.security:def:32195
    P
    Security update for sqlite3 (Important)
    2021-09-23
    oval:org.opensuse.security:def:31686
    P
    Security update for xen (Important)
    2021-09-23
    oval:org.opensuse.security:def:31682
    P
    Security update for openssl (Low)
    2021-09-20
    oval:org.opensuse.security:def:26113
    P
    Security update for mysql-connector-java (Moderate)
    2021-08-30
    oval:org.opensuse.security:def:26110
    P
    Security update for aspell (Important)
    2021-08-25
    oval:org.opensuse.security:def:31249
    P
    Security update for python-PyYAML (Important)
    2021-08-24
    oval:org.opensuse.security:def:26101
    P
    Security update for php74 (Important)
    2021-08-06
    oval:org.opensuse.security:def:31659
    P
    Security update for qemu (Important)
    2021-07-29
    oval:org.opensuse.security:def:26096
    P
    Security update for php72 (Moderate)
    2021-07-29
    oval:org.opensuse.security:def:31238
    P
    Security update for qemu (Important)
    2021-07-29
    oval:org.opensuse.security:def:32156
    P
    Security update for the Linux Kernel (Live Patch 34 for SLE 12 SP3) (Important)
    2021-07-27
    oval:org.opensuse.security:def:31237
    P
    Security update for the Linux Kernel (Live Patch 34 for SLE 12 SP3) (Important)
    2021-07-27
    oval:org.opensuse.security:def:36219
    P
    libsoup-2_4-1-2.32.2-4.13.1 on GA media (Moderate)
    2021-06-08
    oval:org.opensuse.security:def:32938
    P
    Security update for libX11 (Important)
    2021-06-08
    oval:org.opensuse.security:def:36488
    P
    libsoup-devel-2.32.2-4.13.1 on GA media (Moderate)
    2021-06-08
    oval:org.opensuse.security:def:42626
    P
    libsoup-2_4-1-2.32.2-4.13.1 on GA media (Moderate)
    2021-06-08
    oval:org.opensuse.security:def:32107
    P
    Security update for the Linux Kernel (Live Patch 32 for SLE 12 SP3) (Important)
    2021-06-04
    oval:org.opensuse.security:def:26052
    P
    Security update for graphviz (Critical)
    2021-05-19
    oval:org.opensuse.security:def:26053
    P
    Security update for libxml2 (Important)
    2021-05-19
    oval:org.opensuse.security:def:26049
    P
    Security update for lz4 (Important)
    2021-05-14
    oval:org.opensuse.security:def:26038
    P
    Security update for curl (Moderate)
    2021-04-28
    oval:org.opensuse.security:def:31158
    P
    Security update for the Linux Kernel (Live Patch 35 for SLE 12 SP3) (Important)
    2021-04-28
    oval:org.opensuse.security:def:32899
    P
    Security update for xen (Important)
    2021-04-19
    oval:org.opensuse.security:def:31604
    P
    Security update for spamassassin (Important)
    2021-04-12
    oval:org.opensuse.security:def:26203
    P
    Security update for openldap2 (Important)
    2021-03-03
    oval:org.opensuse.security:def:31738
    P
    Security update for grub2 (Important)
    2021-03-02
    oval:org.opensuse.security:def:32261
    P
    Security update for krb5-appl (Important)
    2021-02-19
    oval:org.opensuse.security:def:26194
    P
    Security update for java-1_7_1-ibm (Important)
    2021-02-18
    oval:org.opensuse.security:def:31323
    P
    Security update for the Linux Kernel (Live Patch 35 for SLE 12 SP3) (Important)
    2021-02-10
    oval:org.opensuse.security:def:32139
    P
    Security update for sudo (Important)
    2021-01-26
    oval:org.opensuse.security:def:26037
    P
    Security update for the Linux Kernel (Important)
    2021-01-15
    oval:org.opensuse.security:def:31685
    P
    Security update for java-1_8_0-ibm (Moderate)
    2021-01-05
    oval:org.opensuse.security:def:32013
    P
    Security update for the Linux Kernel (Live Patch 36 for SLE 12 SP3) (Important)
    2020-12-07
    oval:org.opensuse.security:def:31084
    P
    Security update for postgresql12 (Important)
    2020-12-04
    oval:org.opensuse.security:def:25972
    P
    Security update for postgresql12 (Important)
    2020-12-04
    oval:org.opensuse.security:def:35604
    P
    libsoup-2_4-1-2.28.2-0.1.151 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:35770
    P
    libsoup-2_4-1-2.32.2-4.7.1 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:42011
    P
    libsoup-2_4-1-2.28.2-0.1.151 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:35974
    P
    libsoup-2_4-1-2.32.2-4.13.1 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:25332
    P
    Security update for sane-backends (Important)
    2020-12-01
    oval:org.opensuse.security:def:26667
    P
    apache2 on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:26300
    P
    Security update for gimp (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:25769
    P
    Security update for gd (Low)
    2020-12-01
    oval:org.opensuse.security:def:25440
    P
    Security update for python-xdg (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:26769
    P
    libsoup-2_4-1 on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:31072
    P
    Security update for the Linux Kernel (Important)
    2020-12-01
    oval:org.opensuse.security:def:25728
    P
    Security update for python-cffi, python-cryptography (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:31895
    P
    Security update for MozillaFirefox, mozilla-nspr (Important)
    2020-12-01
    oval:org.opensuse.security:def:31991
    P
    Security update for java-1_7_1-ibm (Important)
    2020-12-01
    oval:org.opensuse.security:def:27217
    P
    libsoup-2_4-1 on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:25844
    P
    Security update for the Linux Kernel (Important)
    2020-12-01
    oval:org.opensuse.security:def:25581
    P
    Security update for perl-XML-Twig (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:27451
    P
    libgtop-2_0-7-32bit on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:25866
    P
    Security update for the Linux Kernel (Important)
    2020-12-01
    oval:org.opensuse.security:def:25834
    P
    Security update for the Linux Kernel (Important)
    2020-12-01
    oval:org.opensuse.security:def:32057
    P
    Security update for kvm (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:31442
    P
    Security update for policycoreutils (Low)
    2020-12-01
    oval:org.opensuse.security:def:26322
    P
    Security update for ffmpeg (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:25785
    P
    Security update for flash-player (Critical)
    2020-12-01
    oval:org.opensuse.security:def:32461
    P
    Security update for xorg-x11-libXdmcp (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:25156
    P
    Security update for the Linux Kernel (Important)
    2020-12-01
    oval:org.opensuse.security:def:31455
    P
    Security update for postgresql10 (Important)
    2020-12-01
    oval:org.opensuse.security:def:25524
    P
    Security update for MozillaFirefox (Important)
    2020-12-01
    oval:org.opensuse.security:def:31527
    P
    Security update for Ruby
    2020-12-01
    oval:org.opensuse.security:def:26463
    P
    Security update for enigmail (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:26486
    P
    Security update for pdns-recursor (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:33143
    P
    libcgroup1 on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:25231
    P
    Security update for gcc9 (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:26716
    P
    gvim on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:26734
    P
    ldapsmb on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:25536
    P
    Security update for xen (Important)
    2020-12-01
    oval:org.opensuse.security:def:31995
    P
    Security update for java-1_7_1-ibm (Important)
    2020-12-01
    oval:org.opensuse.security:def:26544
    P
    fetchmail on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:25605
    P
    Security update for MozillaFirefox (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:31847
    P
    Security update for clamav (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:31848
    P
    Security update for clamav (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:27486
    P
    libsoup-devel on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:25746
    P
    Security update for openssl-1_1 (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:32400
    P
    Security update for vim (Important)
    2020-12-01
    oval:org.opensuse.security:def:32530
    P
    hplip on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:25999
    P
    Security update for zziplib (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:31382
    P
    Security update for openvpn
    2020-12-01
    oval:org.opensuse.security:def:25931
    P
    Security update for libcares2 (Low)
    2020-12-01
    oval:org.opensuse.security:def:25321
    P
    Security update for java-1_7_0-openjdk (Important)
    2020-12-01
    oval:org.opensuse.security:def:26345
    P
    Security update for libgit2 (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:26256
    P
    Security update for the Linux Kernel (Important)
    2020-12-01
    oval:org.opensuse.security:def:33182
    P
    libsoup-2_4-1 on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:25768
    P
    Security update for flash-player (Important)
    2020-12-01
    oval:org.opensuse.security:def:31771
    P
    Security update for MozillaFirefox, MozillaFirefox-branding-SLED, firefox-gcc5, mozilla-nss (Important)
    2020-12-01
    oval:org.opensuse.security:def:31526
    P
    Security update for rsyslog (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:26755
    P
    libnetpbm10 on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:26604
    P
    libsoup-2_4-1 on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:25396
    P
    Security update for perl-DBI (Important)
    2020-12-01
    oval:org.opensuse.security:def:31808
    P
    Security update for apache2 (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:31787
    P
    Security update for MozillaFirefox (Important)
    2020-12-01
    oval:org.opensuse.security:def:26938
    P
    libQtWebKit4-32bit on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:25780
    P
    Security update for python (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:25497
    P
    Security update for LibVNCServer (Important)
    2020-12-01
    oval:org.opensuse.security:def:26813
    P
    pyxml on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:31073
    P
    Security update for the Linux Kernel (Important)
    2020-12-01
    oval:org.opensuse.security:def:25809
    P
    Security update for the Linux Kernel (Important)
    2020-12-01
    oval:org.opensuse.security:def:32051
    P
    Security update for kvm (Important)
    2020-12-01
    oval:org.opensuse.security:def:31441
    P
    Security update for pixman (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:26241
    P
    Security update for evolution (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:25732
    P
    Security update for qemu (Important)
    2020-12-01
    oval:org.opensuse.security:def:32439
    P
    Security update for xen (Important)
    2020-12-01
    oval:org.opensuse.security:def:32569
    P
    libsoup-2_4-1 on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:25155
    P
    Security update for xen (Important)
    2020-12-01
    oval:org.opensuse.security:def:25950
    P
    Security update for evince (Important)
    2020-12-01
    oval:org.opensuse.security:def:25873
    P
    Security update for libcares2 (Low)
    2020-12-01
    oval:org.opensuse.security:def:32695
    P
    krb5-doc on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:31453
    P
    Security update for postgresql10 (Low)
    2020-12-01
    oval:org.opensuse.security:def:26379
    P
    Security update for irssi (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:32505
    P
    enscript on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:25167
    P
    Security update for python-PyYAML (Important)
    2020-12-01
    oval:org.opensuse.security:def:31547
    P
    Security update for sblim-sfcb (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:26398
    P
    Security update for pdns-recursor (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:25525
    P
    Security update for ruby2.1 (Important)
    2020-12-01
    oval:org.opensuse.security:def:31903
    P
    Security update for fontconfig (Low)
    2020-12-01
    oval:org.opensuse.security:def:26614
    P
    mozilla-xulrunner190 on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:26500
    P
    Security update for ffmpeg-4 (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:25359
    P
    Security update for SUSE Manager Client Tools (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:31826
    P
    Security update for bind (Important)
    2020-12-01
    oval:org.opensuse.security:def:26973
    P
    libsoup-2_4-1 on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:25600
    P
    Security update for java-1_8_0-ibm (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:32052
    P
    Security update for kvm (Important)
    2020-12-01
    oval:org.opensuse.security:def:31952
    P
    Security update for grub2 (Important)
    2020-12-01
    oval:org.opensuse.security:def:27182
    P
    libexif on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:25662
    P
    Security update for apache-commons-httpclient (Important)
    2020-12-01
    oval:org.opensuse.security:def:32351
    P
    Security update for squid (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:31892
    P
    Security update for expat (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:32295
    P
    Security update for ppp (Important)
    2020-12-01
    oval:org.opensuse.security:def:25897
    P
    Security update for mariadb (Important)
    2020-12-01
    oval:org.opensuse.security:def:25887
    P
    Security update for ImageMagick (Important)
    2020-12-01
    oval:org.opensuse.security:def:32734
    P
    libsoup-2_4-1 on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:25320
    P
    Security update for perl-DBI (Important)
    2020-12-01
    oval:org.opensuse.security:def:26242
    P
    Security update for ibus (Important)
    2020-12-01
    oval:org.opensuse.security:def:31439
    P
    Security update for php53 (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:26447
    P
    Security update for pdns (Important)
    2020-12-01
    oval:org.opensuse.security:def:26569
    P
    kde4-kgreeter-plugins on GA media (Moderate)
    2020-12-01
    oval:org.debian:def:1248
    V
    missing input sanitising
    2007-01-12
    BACK
    libsoup libsoup 2.2.98