Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2024-52531

Опубликовано: 11 нояб. 2024
Источник: debian
EPSS Низкий

Описание

GNOME libsoup before 3.6.1 allows a buffer overflow in applications that perform conversion to UTF-8 in soup_header_parse_param_list_strict. There is a plausible way to reach this remotely via soup_message_headers_get_content_type (e.g., an application may want to retrieve the content type of a request or response).

Пакеты

ПакетСтатусВерсия исправленияРелизТип
libsoup3fixed3.6.0-4package
libsoup3no-dsabookwormpackage
libsoup2.4fixed2.74.3-8.1package
libsoup2.4fixed2.74.3-1+deb12u1bookwormpackage

Примечания

  • https://gitlab.gnome.org/GNOME/libsoup/-/merge_requests/407

  • https://gitlab.gnome.org/GNOME/libsoup/-/commit/3c54033634ae537b52582900a7ba432c52ae8174

  • https://gitlab.gnome.org/GNOME/libsoup/-/commit/a35222dd0bfab2ac97c10e86b95f762456628283

EPSS

Процентиль: 30%
0.00106
Низкий

Связанные уязвимости

CVSS3: 6.5
ubuntu
7 месяцев назад

GNOME libsoup before 3.6.1 allows a buffer overflow in applications that perform conversion to UTF-8 in soup_header_parse_param_list_strict. There is a plausible way to reach this remotely via soup_message_headers_get_content_type (e.g., an application may want to retrieve the content type of a request or response).

CVSS3: 9
redhat
7 месяцев назад

GNOME libsoup before 3.6.1 allows a buffer overflow in applications that perform conversion to UTF-8 in soup_header_parse_param_list_strict. There is a plausible way to reach this remotely via soup_message_headers_get_content_type (e.g., an application may want to retrieve the content type of a request or response).

CVSS3: 6.5
nvd
7 месяцев назад

GNOME libsoup before 3.6.1 allows a buffer overflow in applications that perform conversion to UTF-8 in soup_header_parse_param_list_strict. There is a plausible way to reach this remotely via soup_message_headers_get_content_type (e.g., an application may want to retrieve the content type of a request or response).

CVSS3: 8.4
msrc
7 месяцев назад

Описание отсутствует

rocky
4 месяца назад

Important: libsoup security update

EPSS

Процентиль: 30%
0.00106
Низкий