Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2025-32049

Опубликовано: 03 апр. 2025
Источник: debian
EPSS Низкий

Описание

A flaw was found in libsoup. The SoupWebsocketConnection may accept a large WebSocket message, which may cause libsoup to allocate memory and lead to a denial of service (DoS).

Пакеты

ПакетСтатусВерсия исправленияРелизТип
libsoup3unfixedpackage
libsoup3no-dsabookwormpackage
libsoup2.4unfixedpackage
libsoup2.4no-dsabookwormpackage

Примечания

  • https://gitlab.gnome.org/GNOME/libsoup/-/issues/390

  • https://gitlab.gnome.org/GNOME/libsoup/-/merge_requests/408

  • Proposed fix adds an option with the default retaining old behaviour:

  • https://gitlab.gnome.org/GNOME/libsoup/-/merge_requests/408#note_2394070

EPSS

Процентиль: 63%
0.00447
Низкий

Связанные уязвимости

CVSS3: 7.5
ubuntu
4 месяца назад

A flaw was found in libsoup. The SoupWebsocketConnection may accept a large WebSocket message, which may cause libsoup to allocate memory and lead to a denial of service (DoS).

CVSS3: 7.5
redhat
4 месяца назад

A flaw was found in libsoup. The SoupWebsocketConnection may accept a large WebSocket message, which may cause libsoup to allocate memory and lead to a denial of service (DoS).

CVSS3: 7.5
nvd
4 месяца назад

A flaw was found in libsoup. The SoupWebsocketConnection may accept a large WebSocket message, which may cause libsoup to allocate memory and lead to a denial of service (DoS).

CVSS3: 7.5
github
4 месяца назад

A flaw was found in libsoup. The SoupWebsocketConnection may accept a large WebSocket message, which may cause libsoup to allocate memory and lead to a denial of service (DoS).

CVSS3: 7.5
fstec
около 1 года назад

Уязвимость реализации протокола WebSocket библиотеки libsoup графического интерфейса GNOME, позволяющая нарушителю вызвать отказ в обслуживании

EPSS

Процентиль: 63%
0.00447
Низкий