MGASA-2021-0263
Dashboard / Vulnerabilities / MGASA-2021-0263
MGASA-2021-0263
Summary: Updated gsoap packages fix security vulnerabilities
Details: A denial-of-service vulnerability exists in the WS-Security plugin functionality of Genivia gSOAP 2.8.107. A specially crafted SOAP request can lead to denial of service. An attacker can send an HTTP request to trigger this vulnerability (CVE-2020-13574). A denial-of-service vulnerability exists in the WS-Addressing plugin functionality of Genivia gSOAP 2.8.107. A specially crafted SOAP request can lead to denial of service. An attacker can send an HTTP request to trigger this vulnerability (CVE-2020-13575). A code execution vulnerability exists in the WS-Addressing plugin functionality of Genivia gSOAP 2.8.107. A specially crafted SOAP request can lead to remote code execution. An attacker can send an HTTP request to trigger this vulnerability (CVE-2020-13576). A denial-of-service vulnerability exists in the WS-Security plugin functionality of Genivia gSOAP 2.8.107. A specially crafted SOAP request can lead to denial of service. An attacker can send an HTTP request to trigger this vulnerability (CVE-2020-13577). A denial-of-service vulnerability exists in the WS-Security plugin functionality of Genivia gSOAP 2.8.107. A specially crafted SOAP request can lead to denial of service. An attacker can send an HTTP request to trigger this vulnerability (CVE-2020-13578).
References: https://advisories.mageia.org/MGASA-2021-0263.html, https://bugs.mageia.org/show_bug.cgi?id=29015, https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-13574, https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-13575, https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-13576, https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-13577, https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-13578, https://lists.fedoraproject.org/archives/list/[email protected]/thread/SMTJ3SJJ22SFLBLPKFADV7NVBH7UFA23/
Affected packages
Package
Name: gsoap
Purl: pkg:rpm/mageia/gsoap?arch=source&distro=mageia-7
Affected ranges
Type: ECOSYSTEM
Events:
