Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2024-52532

Опубликовано: 11 нояб. 2024
Источник: redhat
CVSS3: 7.5

Описание

GNOME libsoup before 3.6.1 has an infinite loop, and memory consumption. during the reading of certain patterns of WebSocket data from clients.

A flaw was found in Libsoup. The soup_websocket_connection_read function uses a loop that reads incoming WebSocket data via the glib library. This issue makes it possible to cause the loop to run indefinitely by sending a continuous stream of data to it. The effect will prevent the DCV service from accepting any further connections, leading to a denial of service.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 10libsoup3Not affected
Red Hat Enterprise Linux 7libsoupOut of support scope
Red Hat Enterprise Linux 8libsoupFixedRHSA-2024:957313.11.2024
Red Hat Enterprise Linux 8libsoupFixedRHSA-2024:957313.11.2024
Red Hat Enterprise Linux 9libsoupFixedRHSA-2024:955913.11.2024

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-835
https://bugzilla.redhat.com/show_bug.cgi?id=2325276libsoup: infinite loop while reading websocket data

7.5 High

CVSS3

Связанные уязвимости

CVSS3: 7.5
ubuntu
7 месяцев назад

GNOME libsoup before 3.6.1 has an infinite loop, and memory consumption. during the reading of certain patterns of WebSocket data from clients.

CVSS3: 7.5
nvd
7 месяцев назад

GNOME libsoup before 3.6.1 has an infinite loop, and memory consumption. during the reading of certain patterns of WebSocket data from clients.

CVSS3: 7.5
msrc
7 месяцев назад

Описание отсутствует

CVSS3: 7.5
debian
7 месяцев назад

GNOME libsoup before 3.6.1 has an infinite loop, and memory consumptio ...

CVSS3: 7.5
github
7 месяцев назад

GNOME libsoup before 3.6.1 has an infinite loop, and memory consumption. during the reading of certain patterns of WebSocket data from clients.

7.5 High

CVSS3