Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-wmpg-2mpv-2hmm

Опубликовано: 20 авг. 2026
Источник: github
Github: Не прошло ревью
CVSS3: 5.3

Описание

A flaw was found in libsoup's SoupServer HTTP Range header processing. The sort_ranges() comparator in soup-message-headers.c truncates a 64-bit subtraction result to 32-bit int, flipping the sign for range offsets differing by more than INT_MAX. This causes silent omission of requested byte ranges from HTTP 206 Partial Content responses on resources larger than approximately 2 GB.

A flaw was found in libsoup's SoupServer HTTP Range header processing. The sort_ranges() comparator in soup-message-headers.c truncates a 64-bit subtraction result to 32-bit int, flipping the sign for range offsets differing by more than INT_MAX. This causes silent omission of requested byte ranges from HTTP 206 Partial Content responses on resources larger than approximately 2 GB.

EPSS

Процентиль: 14%
0.00232
Низкий

5.3 Medium

CVSS3

Дефекты

CWE-197

Связанные уязвимости

CVSS3: 5.3
ubuntu
7 дней назад

A flaw was found in libsoup's SoupServer HTTP Range header processing. The sort_ranges() comparator in soup-message-headers.c truncates a 64-bit subtraction result to 32-bit int, flipping the sign for range offsets differing by more than INT_MAX. This causes silent omission of requested byte ranges from HTTP 206 Partial Content responses on resources larger than approximately 2 GB.

CVSS3: 5.3
redhat
около 2 месяцев назад

A flaw was found in libsoup's SoupServer HTTP Range header processing. The sort_ranges() comparator in soup-message-headers.c truncates a 64-bit subtraction result to 32-bit int, flipping the sign for range offsets differing by more than INT_MAX. This causes silent omission of requested byte ranges from HTTP 206 Partial Content responses on resources larger than approximately 2 GB.

CVSS3: 5.3
nvd
7 дней назад

A flaw was found in libsoup's SoupServer HTTP Range header processing. The sort_ranges() comparator in soup-message-headers.c truncates a 64-bit subtraction result to 32-bit int, flipping the sign for range offsets differing by more than INT_MAX. This causes silent omission of requested byte ranges from HTTP 206 Partial Content responses on resources larger than approximately 2 GB.

msrc
3 дня назад

Libsoup: libsoup: integer truncation in sort_ranges() comparator causes silent omission of http range responses

CVSS3: 5.3
debian
7 дней назад

A flaw was found in libsoup's SoupServer HTTP Range header processing. ...

EPSS

Процентиль: 14%
0.00232
Низкий

5.3 Medium

CVSS3

Дефекты

CWE-197