Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2024-52531

Опубликовано: 11 нояб. 2024
Источник: debian
EPSS Низкий

Описание

GNOME libsoup before 3.6.1 allows a buffer overflow in applications that perform conversion to UTF-8 in soup_header_parse_param_list_strict. There is a plausible way to reach this remotely via soup_message_headers_get_content_type (e.g., an application may want to retrieve the content type of a request or response).

Пакеты

ПакетСтатусВерсия исправленияРелизТип
libsoup3fixed3.6.0-4package
libsoup3fixed3.2.3-0+deb12u1bookwormpackage
libsoup2.4fixed2.74.3-8.1package
libsoup2.4fixed2.74.3-1+deb12u1bookwormpackage

Примечания

  • https://gitlab.gnome.org/GNOME/libsoup/-/merge_requests/407

  • https://gitlab.gnome.org/GNOME/libsoup/-/commit/3c54033634ae537b52582900a7ba432c52ae8174

  • https://gitlab.gnome.org/GNOME/libsoup/-/commit/a35222dd0bfab2ac97c10e86b95f762456628283

EPSS

Процентиль: 42%
0.00201
Низкий

Связанные уязвимости

CVSS3: 6.5
ubuntu
11 месяцев назад

GNOME libsoup before 3.6.1 allows a buffer overflow in applications that perform conversion to UTF-8 in soup_header_parse_param_list_strict. There is a plausible way to reach this remotely via soup_message_headers_get_content_type (e.g., an application may want to retrieve the content type of a request or response).

CVSS3: 9
redhat
11 месяцев назад

GNOME libsoup before 3.6.1 allows a buffer overflow in applications that perform conversion to UTF-8 in soup_header_parse_param_list_strict. There is a plausible way to reach this remotely via soup_message_headers_get_content_type (e.g., an application may want to retrieve the content type of a request or response).

CVSS3: 6.5
nvd
11 месяцев назад

GNOME libsoup before 3.6.1 allows a buffer overflow in applications that perform conversion to UTF-8 in soup_header_parse_param_list_strict. There is a plausible way to reach this remotely via soup_message_headers_get_content_type (e.g., an application may want to retrieve the content type of a request or response).

CVSS3: 8.4
msrc
10 месяцев назад

Описание отсутствует

rocky
7 месяцев назад

Important: libsoup security update

EPSS

Процентиль: 42%
0.00201
Низкий