Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2025-2784

Опубликовано: 03 апр. 2025
Источник: debian
EPSS Низкий

Описание

A flaw was found in libsoup. The package is vulnerable to a heap buffer over-read when sniffing content via the skip_insight_whitespace() function. Libsoup clients may read one byte out-of-bounds in response to a crafted HTTP response by an HTTP server.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
libsoup3fixed3.6.5-1package
libsoup3no-dsabookwormpackage
libsoup2.4fixed2.74.3-10package
libsoup2.4no-dsabookwormpackage

Примечания

  • https://gitlab.gnome.org/GNOME/libsoup/-/issues/422

  • Fixed by: https://gitlab.gnome.org/GNOME/libsoup/-/commit/c415ad0b6771992e66c70edf373566c6e247089d (3.6.5)

  • Depends on: https://gitlab.gnome.org/GNOME/libsoup/-/merge_requests/435

  • https://gitlab.gnome.org/GNOME/libsoup/-/commit/242a10fbb12dbdc12d254bd8fc8669a0ac055304 (3.6.5)

EPSS

Процентиль: 76%
0.01032
Низкий

Связанные уязвимости

CVSS3: 7
ubuntu
3 месяца назад

A flaw was found in libsoup. The package is vulnerable to a heap buffer over-read when sniffing content via the skip_insight_whitespace() function. Libsoup clients may read one byte out-of-bounds in response to a crafted HTTP response by an HTTP server.

CVSS3: 7
redhat
3 месяца назад

A flaw was found in libsoup. The package is vulnerable to a heap buffer over-read when sniffing content via the skip_insight_whitespace() function. Libsoup clients may read one byte out-of-bounds in response to a crafted HTTP response by an HTTP server.

CVSS3: 7
nvd
3 месяца назад

A flaw was found in libsoup. The package is vulnerable to a heap buffer over-read when sniffing content via the skip_insight_whitespace() function. Libsoup clients may read one byte out-of-bounds in response to a crafted HTTP response by an HTTP server.

CVSS3: 7
msrc
около 1 месяца назад

Описание отсутствует

CVSS3: 7
github
3 месяца назад

A flaw was found in libsoup. The package is vulnerable to a heap buffer over-read when sniffing content via the skip_insight_whitespace() function. Libsoup clients may read one byte out-of-bounds in response to a crafted HTTP response by an HTTP server.

EPSS

Процентиль: 76%
0.01032
Низкий