SUSE-SU-2018:2204-1
Dashboard / Vulnerabilities / SUSE-SU-2018:2204-1
SUSE-SU-2018:2204-1
Summary: Security update for libsoup
Details: This update for libsoup fixes the following issues: Security issue fixed: - CVE-2018-12910: Fix crash when handling empty hostnames (bsc#1100097). - CVE-2017-2885: Fix chunk decoding buffer overrun that could be exploited against either clients or servers (bsc#1052916). Bug fixes: - bsc#1086036: translation-update-upstream commented out for Leap
References: https://www.suse.com/support/update/announcement/2018/suse-su-20182204-1/, https://bugzilla.suse.com/1052916, https://bugzilla.suse.com/1086036, https://bugzilla.suse.com/1100097, https://www.suse.com/security/cve/CVE-2017-2885, https://www.suse.com/security/cve/CVE-2018-12910
Affected packages
Package
Name: libsoup
Purl: pkg:rpm/suse/libsoup&distro=SUSE%20Linux%20Enterprise%20Desktop%2012%20SP3
Affected ranges
Type: ECOSYSTEM
Events:
