Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2024-52530

Опубликовано: 11 нояб. 2024
Источник: debian
EPSS Низкий

Описание

GNOME libsoup before 3.6.0 allows HTTP request smuggling in some configurations because '\0' characters at the end of header names are ignored, i.e., a "Transfer-Encoding\0: chunked" header is treated the same as a "Transfer-Encoding: chunked" header.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
libsoup3fixed3.5.2-1package
libsoup3no-dsabookwormpackage
libsoup2.4fixed2.74.3-8.1package
libsoup2.4fixed2.74.3-1+deb12u1bookwormpackage

Примечания

  • https://gitlab.gnome.org/GNOME/libsoup/-/issues/377

  • Fixed by: https://gitlab.gnome.org/GNOME/libsoup/-/commit/04df03bc092ac20607f3e150936624d4f536e68b (3.5.2)

EPSS

Процентиль: 31%
0.00116
Низкий

Связанные уязвимости

CVSS3: 7.5
ubuntu
7 месяцев назад

GNOME libsoup before 3.6.0 allows HTTP request smuggling in some configurations because '\0' characters at the end of header names are ignored, i.e., a "Transfer-Encoding\0: chunked" header is treated the same as a "Transfer-Encoding: chunked" header.

CVSS3: 7.5
redhat
7 месяцев назад

GNOME libsoup before 3.6.0 allows HTTP request smuggling in some configurations because '\0' characters at the end of header names are ignored, i.e., a "Transfer-Encoding\0: chunked" header is treated the same as a "Transfer-Encoding: chunked" header.

CVSS3: 7.5
nvd
7 месяцев назад

GNOME libsoup before 3.6.0 allows HTTP request smuggling in some configurations because '\0' characters at the end of header names are ignored, i.e., a "Transfer-Encoding\0: chunked" header is treated the same as a "Transfer-Encoding: chunked" header.

CVSS3: 7.5
msrc
7 месяцев назад

Описание отсутствует

CVSS3: 7.5
github
7 месяцев назад

GNOME libsoup before 3.6.0 allows HTTP request smuggling in some configurations because '\0' characters at the end of header names are ignored, i.e., a "Transfer-Encoding\0: chunked" header is treated the same as a "Transfer-Encoding: chunked" header.

EPSS

Процентиль: 31%
0.00116
Низкий