drucken bookmarks versenden konfigurieren admin pdf Sicherheit: Pufferüberlauf in libsoup
Name: |
Pufferüberlauf in libsoup |
|
ID: |
USN-3383-1 |
|
Distribution: |
Ubuntu |
|
Plattformen: |
Ubuntu 14.04 LTS, Ubuntu 16.04 LTS, Ubuntu 17.04 |
|
Datum: |
Do, 10. August 2017, 23:01 |
|
Referenzen: |
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-2885 |
|
Applikationen: |
libsoup |
|
Originalnachricht |
--===============2142685145135851920== Content-Type: multipart/signed; micalg=pgp-sha512; protocol="application/pgp-signature"; boundary="y5m36xyyu6v4iqwj" Content-Disposition: inline
--y5m36xyyu6v4iqwj Content-Type: text/plain; charset=us-ascii Content-Disposition: inline
========================================================================== Ubuntu Security Notice USN-3383-1 August 10, 2017
libsoup2.4 vulnerability ==========================================================================
A security issue affects these releases of Ubuntu and its derivatives:
- Ubuntu 17.04 - Ubuntu 16.04 LTS - Ubuntu 14.04 LTS
Summary:
Applications using libsoup could be made to crash or run programs as your login if it received specially crafted network traffic.
Software Description: - libsoup2.4: HTTP client/server library for GNOME
Details:
Aleksandar Nikolic discovered a stack based buffer overflow when handling chunked encoding. An attacker could use this to cause a denial of service or possibly execute arbitrary code.
Update instructions:
The problem can be corrected by updating your system to the following package versions:
Ubuntu 17.04: gir1.2-soup-2.4 2.56.0-2ubuntu0.1 libsoup-gnome2.4-1 2.56.0-2ubuntu0.1 libsoup2.4-1 2.56.0-2ubuntu0.1
Ubuntu 16.04 LTS: gir1.2-soup-2.4 2.52.2-1ubuntu0.2 libsoup-gnome2.4-1 2.52.2-1ubuntu0.2 libsoup2.4-1 2.52.2-1ubuntu0.2
Ubuntu 14.04 LTS: gir1.2-soup-2.4 2.44.2-1ubuntu2.2 libsoup-gnome2.4-1 2.44.2-1ubuntu2.2 libsoup2.4-1 2.44.2-1ubuntu2.2
In general, a standard system update will make all the necessary changes.
References: https://www.ubuntu.com/usn/usn-3383-1 CVE-2017-2885
Package Information: https://launchpad.net/ubuntu/+source/libsoup2.4/2.56.0-2ubuntu0.1 https://launchpad.net/ubuntu/+source/libsoup2.4/2.52.2-1ubuntu0.2 https://launchpad.net/ubuntu/+source/libsoup2.4/2.44.2-1ubuntu2.2
--y5m36xyyu6v4iqwj Content-Type: application/pgp-signature; name="signature.asc"
-----BEGIN PGP SIGNATURE-----
iQIcBAABCgAGBQJZjJcwAAoJEC8Jno0AXoH0M0UQAJ5oV7JbYuuTP1YPYA4ZJEmt Mrpm3V76OPnj5Yiom6ErFP1cXpqAlrnZmlQV422Zh5L5ktXnYkmuP8xFZT948Tmu fRKTgSZx1UAHKuHSdY1Lo85IQJWHTC4+rC4Bww4E7RvV7WgGZY5Hp5uJMHestDM4 EcYdUAyETdk/WU8wdk2nG3Ne2CK3TDEOz7q7Gb+Vyrwp4YEBkj/YlWTGKjjkZfsg LzzTGSjSvghrt/WP5sqVjbGgjA9fyesBwkQeIEUJu86C66OK69RZAjVo62JM3UCD Tq1K+hEd0Lf9VPC5DgAJvqhw2QMw5qC2vwERW0vqnK5eF3cqhU91rbLoWizDhu5n /Qk/OKd1IR84qlzrW670VEZ2chaIvc0yDzLDrxbxTlx/cVharWb9YKIleYDPBI6a Vjt2i7Co852mXaWqC1m79i9IaJMNNFidvVQ1rg06xAbCHwoZBPLclA6CMT5gYs4N 77jSW3v6oNi7LDfsonxKvnhN65pgzhbkoqQldgEVdLBygwTnVc7NAt2LZxW7AKYp uy7tElRr6NYsIwZAZZY5rvPgqJsYnrTA7PxVWl6ALSD2R5Fle/0SAvgAG/u/JEE4 7WEa7ig6egxmC5i+bkpqemm4xGJuZfiPQetb/DEGHaekElwG7C0S4pRdWBrwLf++ 0N2pWyCmn3bUtccLB/Hg =+fDL -----END PGP SIGNATURE-----
--y5m36xyyu6v4iqwj--
--===============2142685145135851920== Content-Type: text/plain; charset="us-ascii" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit Content-Disposition: inline
-- ubuntu-security-announce mailing list ubuntu-security-announce@lists.ubuntu.com Modify settings or unsubscribe at: https://lists.ubuntu.com/mailman/listinfo/ubuntu-security-announce
--===============2142685145135851920==--
|
|
|
|