Описание
ELSA-2026-24722: libsoup security update (MODERATE)
[2.62.2-2.0.13]
- Backport fix for CVE-2026-5119 [Orabug: 39527088]
[2.62.2-2.0.11]
- Fixes CVE-2026-0719 CVE-2026-1761 [Orabug: 38958074]
[2.62.2-2.0.9]
- Fix CVE-2025-14523 [Orabug: 38873507]
[2.62.2-2.0.7]
- Backport patch for CVE-2025-4945 and CVE-2025-11021 [Orabug: 38664275]
[2.62.2-2.0.5]
- Fixes CVE-2025-2784 CVE-2025-4948 CVE-2025-32049 [Orabug: 38085184]
- CVE-2025-32906 CVE-2025-32911 CVE-2025-32913 CVE-2025-32914
[2.62.2-2.0.3]
- Fixed CVE-2024-52531 buffer overflow via UTF-8 conversion in
- soup_header_parse_param_list_strict [Orabug: 37557504]
Обновленные пакеты
Oracle Linux 7
Oracle Linux x86_64
libsoup
2.62.2-2.0.13.el7
libsoup-devel
2.62.2-2.0.13.el7
Связанные CVE
Связанные уязвимости
A flaw was found in libsoup. When establishing HTTPS tunnels through a configured HTTP proxy, sensitive session cookies are transmitted in cleartext within the initial HTTP CONNECT request. A network-positioned attacker or a malicious HTTP proxy can intercept these cookies, leading to potential session hijacking or user impersonation.
A flaw was found in libsoup. When establishing HTTPS tunnels through a configured HTTP proxy, sensitive session cookies are transmitted in cleartext within the initial HTTP CONNECT request. A network-positioned attacker or a malicious HTTP proxy can intercept these cookies, leading to potential session hijacking or user impersonation.
A flaw was found in libsoup. When establishing HTTPS tunnels through a configured HTTP proxy, sensitive session cookies are transmitted in cleartext within the initial HTTP CONNECT request. A network-positioned attacker or a malicious HTTP proxy can intercept these cookies, leading to potential session hijacking or user impersonation.
Libsoup: libsoup: information disclosure via cleartext transmission of cookies during https tunnel establishment
A flaw was found in libsoup. When establishing HTTPS tunnels through a ...