Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-vhjq-552g-m4h6

Опубликовано: 25 июл. 2025
Источник: github
Github: Не прошло ревью
CVSS3: 5.5

Описание

A global buffer overflow vulnerability was found in the soup_header_name_to_string function in Libsoup. The soup_header_name_to_string function does not validate the name parameter passed in, and directly accesses soup_header_name_strings[name]. The value of name is controllable, when name exceeds the index range of soup_headr_name_string, it will cause an out-of-bounds access.

A global buffer overflow vulnerability was found in the soup_header_name_to_string function in Libsoup. The soup_header_name_to_string function does not validate the name parameter passed in, and directly accesses soup_header_name_strings[name]. The value of name is controllable, when name exceeds the index range of soup_headr_name_string, it will cause an out-of-bounds access.

5.5 Medium

CVSS3

Дефекты

CWE-787

Связанные уязвимости

ubuntu
3 месяца назад

Rejected reason: Maintainers have included reasons at https://gitlab.gnome.org/GNOME/libsoup/-/issues/465

CVSS3: 5.5
redhat
3 месяца назад

A global buffer overflow vulnerability was found in the soup_header_name_to_string function in Libsoup. The `soup_header_name_to_string` function does not validate the `name` parameter passed in, and directly accesses `soup_header_name_strings[name]`. The value of `name` is controllable, when `name` exceeds the index range of `soup_headr_name_string`, it will cause an out-of-bounds access.

nvd
3 месяца назад

Rejected reason: Maintainers have included reasons at https://gitlab.gnome.org/GNOME/libsoup/-/issues/465

5.5 Medium

CVSS3

Дефекты

CWE-787