Bug#405197: libsoup2.2-8: rhythmbox daap plugin crash triggered remotely

2007-01-07 Thread Josselin Mouette
Le dimanche 07 janvier 2007 à 14:18 +0100, Loïc Minier a écrit : > On Sun, Jan 07, 2007, Moritz Muehlenhoff wrote: > > Joey, please assign a CVE for this. I have an update ready. > > FYI, a completely different fix was committed upstream. Upstream decided to rewrite entirely these functions to b

Bug#405197: libsoup2.2-8: rhythmbox daap plugin crash triggered remotely

2007-01-07 Thread Loïc Minier
On Sun, Jan 07, 2007, Moritz Muehlenhoff wrote: > Joey, please assign a CVE for this. I have an update ready. FYI, a completely different fix was committed upstream. -- Loïc Minier <[EMAIL PROTECTED]>

Bug#405197: libsoup2.2-8: rhythmbox daap plugin crash triggered remotely

2007-01-07 Thread Moritz Muehlenhoff
> > There is a segfault in rhythmbox which can be triggered by running > > nessus 2.2.8 against a box running rhythmbox with daap plugin. Joey, please assign a CVE for this. I have an update ready. Cheers, Moritz -- To UNSUBSCRIBE, email to [EMAIL PROTECTED] with a subject of "unsubscr

Bug#405197: libsoup2.2-8: rhythmbox daap plugin crash triggered remotely

2007-01-02 Thread Josselin Mouette
severity 405197 grave found 405197 2.2.3-2 tag 405197 + security thanks Le lundi 01 janvier 2007 à 18:17 +0100, Roland Lezuo a écrit : > Package: libsoup2.2-8 > Version: 2.2.98-1 > Severity: normal > > There is a segfault in rhythmbox which can be triggered by running > nessus 2.2.8 against a box

Bug#405197: libsoup2.2-8: rhythmbox daap plugin crash triggered remotely

2007-01-01 Thread Roland Lezuo
Package: libsoup2.2-8 Version: 2.2.98-1 Severity: normal There is a segfault in rhythmbox which can be triggered by running nessus 2.2.8 against a box running rhythmbox with daap plugin. I've built a debug version of libsoup from debian sources, here is the trace: #0 0x2b7566eb7d69 in strstr