Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

suse-cvrf логотип

openSUSE-SU-2021:0632-1

Опубликовано: 30 апр. 2021
Источник: suse-cvrf

Описание

Security update for gsoap

This update for gsoap fixes the following issues:

  • CVE-2020-13576: Fixed a remote code execution via specially crafted SOAP request inside the WS-Addressing plugin (boo#1182098)

Список пакетов

openSUSE Leap 15.2
gsoap-devel-2.8.102-lp152.2.3.1
gsoap-doc-2.8.102-lp152.2.3.1
libgsoap-2_8_102-2.8.102-lp152.2.3.1

Описание

A code execution vulnerability exists in the WS-Addressing plugin functionality of Genivia gSOAP 2.8.107. A specially crafted SOAP request can lead to remote code execution. An attacker can send an HTTP request to trigger this vulnerability.


Затронутые продукты
openSUSE Leap 15.2:gsoap-devel-2.8.102-lp152.2.3.1
openSUSE Leap 15.2:gsoap-doc-2.8.102-lp152.2.3.1
openSUSE Leap 15.2:libgsoap-2_8_102-2.8.102-lp152.2.3.1

Ссылки