Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

oracle-oval логотип

ELSA-2025-18183

Опубликовано: 16 окт. 2025
Источник: oracle-oval
Платформа: Oracle Linux 10

Описание

ELSA-2025-18183: libsoup3 security update (IMPORTANT)

[3.6.5-7]

  • Fix handling of invalid dates in cookie expires attribute (CVE-2025-11021)

[3.6.5-6]

  • Add patch for CVE-2025-32907

[3.6.5-5]

  • Fix release field

[3.6.5-4]

  • Fix several CVEs

Обновленные пакеты

Oracle Linux 10

Oracle Linux aarch64

libsoup3

3.6.5-3.el10_0.7

libsoup3-devel

3.6.5-3.el10_0.7

libsoup3-doc

3.6.5-3.el10_0.7

Oracle Linux x86_64

libsoup3

3.6.5-3.el10_0.7

libsoup3-devel

3.6.5-3.el10_0.7

libsoup3-doc

3.6.5-3.el10_0.7

Связанные CVE

Связанные уязвимости

CVSS3: 7.5
ubuntu
около 1 месяца назад

A flaw was found in the cookie date handling logic of the libsoup HTTP library, widely used by GNOME and other applications for web communication. When processing cookies with specially crafted expiration dates, the library may perform an out-of-bounds memory read. This flaw could result in unintended disclosure of memory contents, potentially exposing sensitive information from the process using libsoup.

CVSS3: 7.5
nvd
около 1 месяца назад

A flaw was found in the cookie date handling logic of the libsoup HTTP library, widely used by GNOME and other applications for web communication. When processing cookies with specially crafted expiration dates, the library may perform an out-of-bounds memory read. This flaw could result in unintended disclosure of memory contents, potentially exposing sensitive information from the process using libsoup.

msrc
около 1 месяца назад

Libsoup: out-of-bounds read in cookie date handling of libsoup http library

CVSS3: 7.5
debian
около 1 месяца назад

A flaw was found in the cookie date handling logic of the libsoup HTTP ...

suse-cvrf
15 дней назад

Security update for libsoup