Описание
Security update for gsoap
This update for gsoap fixes the following issues:
- CVE-2020-13576: Fixed a remote code execution via specially crafted SOAP request inside the WS-Addressing plugin (boo#1182098)
Список пакетов
openSUSE Leap 15.2
gsoap-devel-2.8.102-lp152.2.3.1
gsoap-doc-2.8.102-lp152.2.3.1
libgsoap-2_8_102-2.8.102-lp152.2.3.1
Ссылки
- E-Mail link for openSUSE-SU-2021:0632-1
- SUSE Security Ratings
- SUSE Bug 1182098
- SUSE CVE CVE-2020-13576 page
Описание
A code execution vulnerability exists in the WS-Addressing plugin functionality of Genivia gSOAP 2.8.107. A specially crafted SOAP request can lead to remote code execution. An attacker can send an HTTP request to trigger this vulnerability.
Затронутые продукты
openSUSE Leap 15.2:gsoap-devel-2.8.102-lp152.2.3.1
openSUSE Leap 15.2:gsoap-doc-2.8.102-lp152.2.3.1
openSUSE Leap 15.2:libgsoap-2_8_102-2.8.102-lp152.2.3.1
Ссылки
- CVE-2020-13576
- SUSE Bug 1182098