Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2025-32906

Опубликовано: 14 апр. 2025
Источник: debian
EPSS Низкий

Описание

A flaw was found in libsoup, where the soup_headers_parse_request() function may be vulnerable to an out-of-bound read. This flaw allows a malicious user to use a specially crafted HTTP request to crash the HTTP server.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
libsoup3fixed3.6.5-1package
libsoup3fixed3.2.3-0+deb12u1bookwormpackage
libsoup2.4fixed2.74.3-10.1package
libsoup2.4no-dsabookwormpackage

Примечания

  • https://gitlab.gnome.org/GNOME/libsoup/-/issues/404

  • Same underlying issue as https://gitlab.gnome.org/GNOME/libsoup/-/issues/407

  • https://gitlab.gnome.org/GNOME/libsoup/-/merge_requests/440

  • Fixed by: https://gitlab.gnome.org/GNOME/libsoup/-/commit/af5b9a4a3945c52b940d5ac181ef51bb12011f1f (3.6.5)

EPSS

Процентиль: 55%
0.0033
Низкий

Связанные уязвимости

CVSS3: 7.5
ubuntu
7 месяцев назад

A flaw was found in libsoup, where the soup_headers_parse_request() function may be vulnerable to an out-of-bound read. This flaw allows a malicious user to use a specially crafted HTTP request to crash the HTTP server.

CVSS3: 7.5
redhat
7 месяцев назад

A flaw was found in libsoup, where the soup_headers_parse_request() function may be vulnerable to an out-of-bound read. This flaw allows a malicious user to use a specially crafted HTTP request to crash the HTTP server.

CVSS3: 7.5
nvd
7 месяцев назад

A flaw was found in libsoup, where the soup_headers_parse_request() function may be vulnerable to an out-of-bound read. This flaw allows a malicious user to use a specially crafted HTTP request to crash the HTTP server.

CVSS3: 7.5
msrc
7 месяцев назад

Libsoup: out of bounds reads in soup_headers_parse_request()

CVSS3: 7.5
github
7 месяцев назад

A flaw was found in libsoup, where the soup_headers_parse_request() function may be vulnerable to an out-of-bound read. This flaw allows a malicious user to use a specially crafted HTTP request to crash the HTTP server.

EPSS

Процентиль: 55%
0.0033
Низкий