Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

oracle-oval логотип

ELSA-2026-19356

Опубликовано: 23 июн. 2026
Источник: oracle-oval
Платформа: Oracle Linux 9

Описание

ELSA-2026-19356: libsoup security update (MODERATE)

[2.72.0-16.1]

  • Backport patch for CVE-2026-5119

[2.72.0-16]

  • Backport patch for CVE-2026-1761

[2.72.0-15]

  • Backport patch for CVE-2026-0719
  • Fix NTLM authentication test failures in FIPS mode

[2.72.0-14]

  • Backport patch for CVE-2025-14523

[2.72.0-13]

  • Backport patch for CVE-2025-4945 and CVE-2025-11021

Обновленные пакеты

Oracle Linux 9

Oracle Linux aarch64

libsoup

2.72.0-16.el9_8.1

libsoup-devel

2.72.0-16.el9_8.1

Oracle Linux x86_64

libsoup

2.72.0-16.el9_8.1

libsoup-devel

2.72.0-16.el9_8.1

Связанные CVE

Связанные уязвимости

CVSS3: 5.9
ubuntu
4 месяца назад

A flaw was found in libsoup. When establishing HTTPS tunnels through a configured HTTP proxy, sensitive session cookies are transmitted in cleartext within the initial HTTP CONNECT request. A network-positioned attacker or a malicious HTTP proxy can intercept these cookies, leading to potential session hijacking or user impersonation.

CVSS3: 5.9
redhat
4 месяца назад

A flaw was found in libsoup. When establishing HTTPS tunnels through a configured HTTP proxy, sensitive session cookies are transmitted in cleartext within the initial HTTP CONNECT request. A network-positioned attacker or a malicious HTTP proxy can intercept these cookies, leading to potential session hijacking or user impersonation.

CVSS3: 5.9
nvd
4 месяца назад

A flaw was found in libsoup. When establishing HTTPS tunnels through a configured HTTP proxy, sensitive session cookies are transmitted in cleartext within the initial HTTP CONNECT request. A network-positioned attacker or a malicious HTTP proxy can intercept these cookies, leading to potential session hijacking or user impersonation.

msrc
4 месяца назад

Libsoup: libsoup: information disclosure via cleartext transmission of cookies during https tunnel establishment

CVSS3: 5.9
debian
4 месяца назад

A flaw was found in libsoup. When establishing HTTPS tunnels through a ...