Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2025-32911

Опубликовано: 15 апр. 2025
Источник: debian
EPSS Низкий

Описание

A use-after-free type vulnerability was found in libsoup, in the soup_message_headers_get_content_disposition() function. This flaw allows a malicious HTTP client to cause memory corruption in the libsoup server.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
libsoup3fixed3.6.4-1package
libsoup3no-dsabookwormpackage
libsoup2.4fixed2.74.3-10.1package
libsoup2.4no-dsabookwormpackage

Примечания

  • https://gitlab.gnome.org/GNOME/libsoup/-/issues/433

  • https://gitlab.gnome.org/GNOME/libsoup/-/merge_requests/422

  • Fixed by: https://gitlab.gnome.org/GNOME/libsoup/-/commit/f4a761fb66512fff59798765e8ac5b9e57dceef0 (3.6.2)

EPSS

Процентиль: 28%
0.00097
Низкий

Связанные уязвимости

CVSS3: 9
ubuntu
2 месяца назад

A use-after-free type vulnerability was found in libsoup, in the soup_message_headers_get_content_disposition() function. This flaw allows a malicious HTTP client to cause memory corruption in the libsoup server.

CVSS3: 9
redhat
2 месяца назад

A use-after-free type vulnerability was found in libsoup, in the soup_message_headers_get_content_disposition() function. This flaw allows a malicious HTTP client to cause memory corruption in the libsoup server.

CVSS3: 9
nvd
2 месяца назад

A use-after-free type vulnerability was found in libsoup, in the soup_message_headers_get_content_disposition() function. This flaw allows a malicious HTTP client to cause memory corruption in the libsoup server.

CVSS3: 9
github
2 месяца назад

A flaw was found in libsoup, which is vulnerable to a use-after-free memory issue not on the heap in the soup_message_headers_get_content_disposition() function. This flaw allows a malicious HTTP client to cause memory corruption in the libsoup server.

CVSS3: 9
fstec
2 месяца назад

Уязвимость функции soup_message_headers_get_content_disposition() библиотеки libsoup графического интерфейса GNOME, позволяющая нарушителю выполнить произвольный код

EPSS

Процентиль: 28%
0.00097
Низкий