Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

oracle-oval логотип

ELSA-2025-19714

Опубликовано: 04 нояб. 2025
Источник: oracle-oval
Платформа: Oracle Linux 8

Описание

ELSA-2025-19714: libsoup security update (IMPORTANT)

[2.62.3-10]

  • Backport patch for CVE-2025-4945 and CVE-2025-11021

Обновленные пакеты

Oracle Linux 8

Oracle Linux aarch64

libsoup

2.62.3-10.el8_10

libsoup-devel

2.62.3-10.el8_10

Oracle Linux x86_64

libsoup

2.62.3-10.el8_10

libsoup-devel

2.62.3-10.el8_10

Связанные CVE

Связанные уязвимости

rocky
3 дня назад

Important: libsoup security update

oracle-oval
4 дня назад

ELSA-2025-19713: libsoup security update (IMPORTANT)

CVSS3: 7.5
ubuntu
около 1 месяца назад

A flaw was found in the cookie date handling logic of the libsoup HTTP library, widely used by GNOME and other applications for web communication. When processing cookies with specially crafted expiration dates, the library may perform an out-of-bounds memory read. This flaw could result in unintended disclosure of memory contents, potentially exposing sensitive information from the process using libsoup.

CVSS3: 7.5
nvd
около 1 месяца назад

A flaw was found in the cookie date handling logic of the libsoup HTTP library, widely used by GNOME and other applications for web communication. When processing cookies with specially crafted expiration dates, the library may perform an out-of-bounds memory read. This flaw could result in unintended disclosure of memory contents, potentially exposing sensitive information from the process using libsoup.

msrc
около 1 месяца назад

Libsoup: out-of-bounds read in cookie date handling of libsoup http library