package: libsoup
severity: grave
tags: security

it has been found that libsoup is vulnerable to an integer overflow
attack, see CVE-2009-0585 [1].  details are:

  Integer overflow in the soup_base64_encode function in soup-misc.c in
  libsoup 2.x.x before 2.2.x, and 2.x before 2.24, allows
  context-dependent attackers to execute arbitrary code via a long
  string that is converted to a base64 representation.

since this allows remote attackers to execute arbitrary code, it
should be treated with high urgency.

this was just fixed in ubuntu, so it may be possible to adopt their
patch [2].

if you fix these vulnerabilities, please make sure to include the CVE
id in your changelog.  please contact the security team to coordinate
a fix for stable and/or if you have any questions.

regards,
mike

[1] http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0585
[2] http://www.ubuntu.com/usn/USN-737-1



-- 
To UNSUBSCRIBE, email to debian-bugs-rc-requ...@lists.debian.org
with a subject of "unsubscribe". Trouble? Contact listmas...@lists.debian.org

Reply via email to