Описание
The get_cookies function in soup-cookie-jar.c in libsoup 2.63.2 allows attackers to have unspecified impact via an empty hostname.
An out-of-bounds read has been discovered in libsoup when getting cookies from a URI with empty hostname. An attacker may use this flaw to cause a crash in the application.
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| Red Hat Enterprise Linux 6 | libsoup | Will not fix | ||
| Red Hat Enterprise Linux 8 | libsoup | Not affected | ||
| Red Hat Enterprise Linux 7 | accountsservice | Fixed | RHSA-2018:3140 | 30.10.2018 |
| Red Hat Enterprise Linux 7 | adwaita-icon-theme | Fixed | RHSA-2018:3140 | 30.10.2018 |
| Red Hat Enterprise Linux 7 | appstream-data | Fixed | RHSA-2018:3140 | 30.10.2018 |
| Red Hat Enterprise Linux 7 | atk | Fixed | RHSA-2018:3140 | 30.10.2018 |
| Red Hat Enterprise Linux 7 | at-spi2-atk | Fixed | RHSA-2018:3140 | 30.10.2018 |
| Red Hat Enterprise Linux 7 | at-spi2-core | Fixed | RHSA-2018:3140 | 30.10.2018 |
| Red Hat Enterprise Linux 7 | baobab | Fixed | RHSA-2018:3140 | 30.10.2018 |
| Red Hat Enterprise Linux 7 | bolt | Fixed | RHSA-2018:3140 | 30.10.2018 |
Показывать по
Дополнительная информация
Статус:
5.3 Medium
CVSS3
Связанные уязвимости
The get_cookies function in soup-cookie-jar.c in libsoup 2.63.2 allows attackers to have unspecified impact via an empty hostname.
The get_cookies function in soup-cookie-jar.c in libsoup 2.63.2 allows attackers to have unspecified impact via an empty hostname.
The get_cookies function in soup-cookie-jar.c in libsoup 2.63.2 allows ...
The get_cookies function in soup-cookie-jar.c in libsoup 2.63.2 allows attackers to have unspecified impact via an empty hostname.
5.3 Medium
CVSS3