-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Thu, 14 Feb 2019 17:12:12 +0100 Source: gsoap Binary: libgsoap10 libgsoap-dev gsoap gsoap-doc libgsoap-dbg gsoap-dbg Architecture: source amd64 all Version: 2.8.35-4+deb9u2 Distribution: stretch Urgency: medium Maintainer: Mattias Ellert Changed-By: Mattias Ellert Description: gsoap - Stub generators for gSOAP gsoap-dbg - Debugging symbols for gSOAP stub generators gsoap-doc - gSOAP documentation libgsoap-dbg - Debugging symbols for gSOAP libraries libgsoap-dev - Development libraries and headers for gSOAP libgsoap10 - Runtime libraries for gSOAP Changes: gsoap (2.8.35-4+deb9u2) stretch; urgency=medium . * Fix for CVE-2019-7659 Genivia gSOAP 2.7.x and 2.8.x before 2.8.75 allows attackers to cause a denial of service (application abort) or possibly have unspecified other impact if a server application is built with the -DWITH_COOKIES flag. This affects the C/C++ libgsoapck/libgsoapck++ and libgsoapssl/libgsoapssl++ libraries, as these are built with that flag. * Fix issue with DIME protocol receiver and malformed DIME headers This patch addresses a critical issue with the DIME protocol receiver that may cause the receiver to become unresponsive when a malformed DIME protocol message is received. -- https://www.genivia.com/advisory.html Checksums-Sha1: 44bbef2c2f4d5e4b5901256a5c4061571ead6e47 2199 gsoap_2.8.35-4+deb9u2.dsc 34b8e916aca590d16345d714d051d8786545d160 5723766 gsoap_2.8.35.orig.tar.gz 21f1975da87375a05db0e4aac759519dc17c7c43 13876 gsoap_2.8.35-4+deb9u2.debian.tar.xz bd785113f9226a597b3a0683dc585a08d90f5b30 4092134 gsoap-dbg_2.8.35-4+deb9u2_amd64.deb 02ed4533ae7b67ca5cb55c37331a15ed64a8bbf8 11384966 gsoap-doc_2.8.35-4+deb9u2_all.deb 1532087cd89de912ca2c4b661529c5f449c60066 8901 gsoap_2.8.35-4+deb9u2_amd64.buildinfo a04df1d79a2176e06cc1aa13b13157ce557bef25 943224 gsoap_2.8.35-4+deb9u2_amd64.deb bcfe1860d3bedf4cc76657bffc9eee81487b0b36 1215818 libgsoap-dbg_2.8.35-4+deb9u2_amd64.deb 6c1f17a8495c11f847c4eabfc7888d9f0327def5 265738 libgsoap-dev_2.8.35-4+deb9u2_amd64.deb 455507285a60e4dd54770c3c12afada1ac13db38 265034 libgsoap10_2.8.35-4+deb9u2_amd64.deb Checksums-Sha256: b9d55969bf69d8e9c0cecdc2b031fa34635f4e87abfa4380c04aae27e5f00537 2199 gsoap_2.8.35-4+deb9u2.dsc 20d607d499ec347c0ba21c926bba09da232f53f4da90c47f20a6a67970c1fb5e 5723766 gsoap_2.8.35.orig.tar.gz 171fcaca0c86537cebcc517eef12a41e7428b10f96dd7b38cad5969e2d1bad4e 13876 gsoap_2.8.35-4+deb9u2.debian.tar.xz 781654fffdc473297827a19038417a40d3cd36d903722439ebe6ed863ef4e5a0 4092134 gsoap-dbg_2.8.35-4+deb9u2_amd64.deb 0697d2aeaab1355f1194f6a5da0825a2f36c3817fe18f6947d1d21d7f2e59967 11384966 gsoap-doc_2.8.35-4+deb9u2_all.deb 87e1db7071737dedc30bbc2789787665a51c7c4363574b116dff89a6b7355743 8901 gsoap_2.8.35-4+deb9u2_amd64.buildinfo 32e7d85bb00550e0d00868f4faff23ff3b32a4a3f94bcccd2900b9b12538841c 943224 gsoap_2.8.35-4+deb9u2_amd64.deb 257701df5c3515b5d243c93c168ad248f940d30d83d81d0ec1139730c615c6a6 1215818 libgsoap-dbg_2.8.35-4+deb9u2_amd64.deb be5e76c5dc5e3aa0199b8729d18f813b1701d7a6681c64d73feaec8349c16bbd 265738 libgsoap-dev_2.8.35-4+deb9u2_amd64.deb 3d0b39b0f496024548b02e2fa77063a49b7653a7a0ddb000450083b4f9c40618 265034 libgsoap10_2.8.35-4+deb9u2_amd64.deb Files: b3e242559f83599bb6ac2339188bad30 2199 devel optional gsoap_2.8.35-4+deb9u2.dsc 78c05da816e30e59c2df69dbb6ab2dea 5723766 devel optional gsoap_2.8.35.orig.tar.gz f33185ccf0a9364a9d178571ef7770f1 13876 devel optional gsoap_2.8.35-4+deb9u2.debian.tar.xz 4a1b433714ff04a0dfc63ac8e368ac50 4092134 debug extra gsoap-dbg_2.8.35-4+deb9u2_amd64.deb 86e427799faf00978754b693657c3a9e 11384966 doc optional gsoap-doc_2.8.35-4+deb9u2_all.deb 610b96394b8a8f7915ede21731fef1db 8901 devel optional gsoap_2.8.35-4+deb9u2_amd64.buildinfo f7fd2828ec45eb7c897a521ca3e9e259 943224 devel optional gsoap_2.8.35-4+deb9u2_amd64.deb bea8513842df0dc89b8ebb67d5e3edc0 1215818 debug extra libgsoap-dbg_2.8.35-4+deb9u2_amd64.deb da039c2789b48655a2ed803d589c47f3 265738 libdevel optional libgsoap-dev_2.8.35-4+deb9u2_amd64.deb a2c79dc10d9fbd35a6ba4cbd9b247e28 265034 libs optional libgsoap10_2.8.35-4+deb9u2_amd64.deb -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEE6hgwr99NQxrZ4RRS6K7C/zvhqUsFAlxnBfEACgkQ6K7C/zvh qUukKQ/+OhVnd4y2bdByJMpzDZFUgQrprUs/v2jIDMNaMX9b1zBYkAoBPheIP4pQ 80+tbvEQLlvfIBvO1PY7zjBMO0D1NWwNEA+LbBKwGiglnzDjn16pxHzat5l7Hqir meHqhKa9g5MxOQhXXjL/eo9Al5fS5hc+eiar1aAeFQnpzhxsn1m4Lmh9Hn3KVDtY 6UdaFwVMkVMJBSNobtQNX2RpUwy3ypEwUpwCH7ZaXEHHh8zozfAtgFD+ZuhroMpC /8qV43I5FCdsNv57xvEiWtFeeG94JIGf3vyIhqIGiu7U159BolZ7bxeVReCvXeJI UDzfPsxCu0dKSOZIThb65qqd5AH7yNZicTSFK+pbdNT2LIAaudas8W3Kz3ckygGD Nu21x3lq4T2wAuktcJP7AklvFpYm6fMQY4aksIDD5EbHDZWTguMVdy2lGx+I3UGC k80d/qf7k80X0xMZi952yieYjLj7eJt0054tuwsSSZCcxqbwbmZ4oYBmJ1cWEbwh w8LCk0dqhI3nq5I4OKCfgKRYY86jM6lZvBreJw0ILJ+jIYrN4w4nYbDlNhpJ/wry vyO2N+d6YTxrFfzHIdVdV8YXf9MHUk+Sqqfl6FHhxwAuHuq29wgvidlVk3UyiUWP t2sYXjlGAbsgKbEpTKPrLKkdpPV+OvG0fwD7mHVKrWdMSCrHz28= =fm8M -----END PGP SIGNATURE-----