Openwall GNU/*/Linux - a small security-enhanced Linux distro for servers
[<prev] [next>] [thread-next>] [day] [month] [year] [list]
Date: Tue, 17 Feb 2015 10:15:57 +0000
From: Patrick Coleman <>
Subject: CVE request: vulnerabilities in libcsoap


A number of vulnerabilities exist in nanohttp, a lightweight webserver library
included with libcsoap ( Patches are
provided below against

* Remote buffer overflow
If the server is misconfigured, a remote user can trigger a buffer
overflow by requesting a resource of a certain length.

* Remote null pointer dereference
A remote user can cause a null pointer dereference by sending a
malformed Authorization: header.

Please let me know if you req



Powered by blists - more mailing lists

Your e-mail address:

Please check out the Open Source Software Security Wiki, which is counterpart to this mailing list.

Powered by Openwall GNU/*/Linux - Powered by OpenVZ