Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

oracle-oval логотип

ELSA-2025-18183

Опубликовано: 16 окт. 2025
Источник: oracle-oval
Платформа: Oracle Linux 10

Описание

ELSA-2025-18183: libsoup3 security update (IMPORTANT)

[3.6.5-7]

  • Fix handling of invalid dates in cookie expires attribute (CVE-2025-11021)

[3.6.5-6]

  • Add patch for CVE-2025-32907

[3.6.5-5]

  • Fix release field

[3.6.5-4]

  • Fix several CVEs

Обновленные пакеты

Oracle Linux 10

Oracle Linux aarch64

libsoup3

3.6.5-3.el10_0.7

libsoup3-devel

3.6.5-3.el10_0.7

libsoup3-doc

3.6.5-3.el10_0.7

Oracle Linux x86_64

libsoup3

3.6.5-3.el10_0.7

libsoup3-devel

3.6.5-3.el10_0.7

libsoup3-doc

3.6.5-3.el10_0.7

Связанные CVE

Связанные уязвимости

CVSS3: 7.5
ubuntu
3 месяца назад

A flaw was found in the cookie date handling logic of the libsoup HTTP library, widely used by GNOME and other applications for web communication. When processing cookies with specially crafted expiration dates, the library may perform an out-of-bounds memory read. This flaw could result in unintended disclosure of memory contents, potentially exposing sensitive information from the process using libsoup.

CVSS3: 7.5
nvd
3 месяца назад

A flaw was found in the cookie date handling logic of the libsoup HTTP library, widely used by GNOME and other applications for web communication. When processing cookies with specially crafted expiration dates, the library may perform an out-of-bounds memory read. This flaw could result in unintended disclosure of memory contents, potentially exposing sensitive information from the process using libsoup.

msrc
3 месяца назад

Libsoup: out-of-bounds read in cookie date handling of libsoup http library

CVSS3: 7.5
debian
3 месяца назад

A flaw was found in the cookie date handling logic of the libsoup HTTP ...

suse-cvrf
2 месяца назад

Security update for libsoup