USN-411-1: libsoup vulnerability

23 January 2007

libsoup vulnerability

A security issue affects these releases of Ubuntu and its derivatives:

  • Ubuntu 6.10
  • Ubuntu 6.06 LTS
  • Ubuntu 5.10

Software Description


Roland Lezuo and Josselin Mouette discovered that the HTTP server code in libsoup did not correctly verify request headers. Remote attackers could crash applications using libsoup by sending a crafted HTTP request, resulting in a denial of service.

Update instructions

The problem can be corrected by updating your system to the following package versions:

Ubuntu 6.10
libsoup2.2-8 - 2.2.96-0ubuntu2.1
Ubuntu 6.06 LTS
libsoup2.2-8 - 2.2.93-0ubuntu1.1
Ubuntu 5.10
libsoup2.2-8 -

To update your system, please follow these instructions:

In general, a standard system upgrade is sufficient to effect the necessary changes.