Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

oracle-oval логотип

ELSA-2026-24722

Опубликовано: 29 июн. 2026
Источник: oracle-oval
Платформа: Oracle Linux 7

Описание

ELSA-2026-24722: libsoup security update (MODERATE)

[2.62.2-2.0.13]

  • Backport fix for CVE-2026-5119 [Orabug: 39527088]

[2.62.2-2.0.11]

  • Fixes CVE-2026-0719 CVE-2026-1761 [Orabug: 38958074]

[2.62.2-2.0.9]

  • Fix CVE-2025-14523 [Orabug: 38873507]

[2.62.2-2.0.7]

  • Backport patch for CVE-2025-4945 and CVE-2025-11021 [Orabug: 38664275]

[2.62.2-2.0.5]

  • Fixes CVE-2025-2784 CVE-2025-4948 CVE-2025-32049 [Orabug: 38085184]
  • CVE-2025-32906 CVE-2025-32911 CVE-2025-32913 CVE-2025-32914

[2.62.2-2.0.3]

  • Fixed CVE-2024-52531 buffer overflow via UTF-8 conversion in
  • soup_header_parse_param_list_strict [Orabug: 37557504]

Обновленные пакеты

Oracle Linux 7

Oracle Linux x86_64

libsoup

2.62.2-2.0.13.el7

libsoup-devel

2.62.2-2.0.13.el7

Связанные CVE

Связанные уязвимости

CVSS3: 5.9
ubuntu
4 месяца назад

A flaw was found in libsoup. When establishing HTTPS tunnels through a configured HTTP proxy, sensitive session cookies are transmitted in cleartext within the initial HTTP CONNECT request. A network-positioned attacker or a malicious HTTP proxy can intercept these cookies, leading to potential session hijacking or user impersonation.

CVSS3: 5.9
redhat
4 месяца назад

A flaw was found in libsoup. When establishing HTTPS tunnels through a configured HTTP proxy, sensitive session cookies are transmitted in cleartext within the initial HTTP CONNECT request. A network-positioned attacker or a malicious HTTP proxy can intercept these cookies, leading to potential session hijacking or user impersonation.

CVSS3: 5.9
nvd
4 месяца назад

A flaw was found in libsoup. When establishing HTTPS tunnels through a configured HTTP proxy, sensitive session cookies are transmitted in cleartext within the initial HTTP CONNECT request. A network-positioned attacker or a malicious HTTP proxy can intercept these cookies, leading to potential session hijacking or user impersonation.

msrc
4 месяца назад

Libsoup: libsoup: information disclosure via cleartext transmission of cookies during https tunnel establishment

CVSS3: 5.9
debian
4 месяца назад

A flaw was found in libsoup. When establishing HTTPS tunnels through a ...