CVE-2019-7659

Genivia gSOAP 2.7.x and 2.8.x before 2.8.75 allows attackers to cause a denial of service (application abort) or possibly have unspecified other impact if a server application is built with the -DWITH_COOKIES flag. This affects the C/C++ libgsoapck/libgsoapck++ and libgsoapssl/libgsoapssl++ libraries, as these are built with that flag.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:genivia:gsoap:*:*:*:*:*:*:*:*
cpe:2.3:a:genivia:gsoap:*:*:*:*:*:*:*:*

Configuration 2 (hide)

cpe:2.3:o:debian:debian_linux:8.0:*:*:*:*:*:*:*

History

21 Nov 2024, 04:48

Type Values Removed Values Added
References () https://lists.debian.org/debian-lts-announce/2019/02/msg00027.html - Mailing List, Third Party Advisory () https://lists.debian.org/debian-lts-announce/2019/02/msg00027.html - Mailing List, Third Party Advisory
References () https://outpost24.com/blog/gsoap-vulnerability-identified - () https://outpost24.com/blog/gsoap-vulnerability-identified -
References () https://www.genivia.com/advisory.html#Bug_in_gSOAP_versions_2.7.0_to_2.8.74_for_applications_built_with_the_WITH_COOKIES_flag_enabled_%28Jan_14%2C_2019%29 - () https://www.genivia.com/advisory.html#Bug_in_gSOAP_versions_2.7.0_to_2.8.74_for_applications_built_with_the_WITH_COOKIES_flag_enabled_%28Jan_14%2C_2019%29 -

07 Nov 2023, 03:13

Type Values Removed Values Added
References
  • {'url': 'https://www.genivia.com/advisory.html#Bug_in_gSOAP_versions_2.7.0_to_2.8.74_for_applications_built_with_the_WITH_COOKIES_flag_enabled_(Jan_14,_2019)', 'name': 'https://www.genivia.com/advisory.html#Bug_in_gSOAP_versions_2.7.0_to_2.8.74_for_applications_built_with_the_WITH_COOKIES_flag_enabled_(Jan_14,_2019)', 'tags': ['Exploit', 'Vendor Advisory'], 'refsource': 'CONFIRM'}
  • () https://www.genivia.com/advisory.html#Bug_in_gSOAP_versions_2.7.0_to_2.8.74_for_applications_built_with_the_WITH_COOKIES_flag_enabled_%28Jan_14%2C_2019%29 -

Information

Published : 2019-02-09 14:29

Updated : 2024-11-21 04:48


NVD link : CVE-2019-7659

Mitre link : CVE-2019-7659

CVE.ORG link : CVE-2019-7659


JSON object : View

Products Affected

debian

  • debian_linux

genivia

  • gsoap
CWE
CWE-787

Out-of-bounds Write