USN-2950-2: libsoup update
USN-2950-2: libsoup update Ubuntu Security Notice USN-2950-2 27th April, 2016 libsoup2.4 update A security issue affects these releases of Ubuntu and its derivatives: Ubuntu 16.04 LTS Ubuntu 15.10 Ubuntu 14.04 LTS Summary This update fixes libsoup NTLM authentication. Software description libsoup2.4 – HTTP client/server library for GNOME Details USN-2950-1 fixed vulnerabilities in Samba. The updated Samba packagesintroduced a compatibility issue with NTLM authentication in libsoup. Thisupdate fixes the problem. We apologize for the inconvenience. Original advisory details: Jouni Knuutinen discovered that Samba contained multiple flaws in the DCE/RPC implementation. A remote attacker could use this issue to perform a denial of service, downgrade secure connections by performing a man in the middle attack, or possibly execute arbitrary code. (CVE-2015-5370) Stefan Metzmacher discovered that Samba contained multiple flaws in the NTLMSSP authentication implementation. A remote attacker could use this issue to [ more… ]