USN-411-1: libsoup vulnerability

Ubuntu Security Notice USN-411-1

23rd January, 2007

libsoup vulnerability

A security issue affects these releases of Ubuntu and its derivatives:

  • Ubuntu 6.10
  • Ubuntu 6.06 LTS
  • Ubuntu 5.10

Details

Roland Lezuo and Josselin Mouette discovered that the HTTP server code
in libsoup did not correctly verify request headers. Remote attackers
could crash applications using libsoup by sending a crafted HTTP
request, resulting in a denial of service.

Update instructions

The problem can be corrected by updating your system to the following package version:

Ubuntu 6.10:
libsoup2.2-8 2.2.96-0ubuntu2.1
Ubuntu 6.06 LTS:
libsoup2.2-8 2.2.93-0ubuntu1.1
Ubuntu 5.10:
libsoup2.2-8 2.2.6.1-0ubuntu1.1

To update your system, please follow these instructions: https://wiki.ubuntu.com/Security/Upgrades.

In general, a standard system upgrade is sufficient to effect the
necessary changes.

References

CVE-2006-5876