Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2025-2784

Опубликовано: 25 мар. 2025
Источник: redhat
CVSS3: 7

Описание

A flaw was found in libsoup. The package is vulnerable to a heap buffer over-read when sniffing content via the skip_insight_whitespace() function. Libsoup clients may read one byte out-of-bounds in response to a crafted HTTP response by an HTTP server.

Отчет

Red Hat rates this with a Moderate impact as the flaw may be targeting Confidentiality and Integrity specific to each request.

Меры по смягчению последствий

Currently no mitigation is available for this vulnerability.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 6libsoupOut of support scope
Red Hat Enterprise Linux 10libsoup3FixedRHSA-2025:750513.05.2025
Red Hat Enterprise Linux 7 Extended Lifecycle SupportlibsoupFixedRHSA-2025:917917.06.2025
Red Hat Enterprise Linux 8libsoupFixedRHSA-2025:813226.05.2025
Red Hat Enterprise Linux 8libsoupFixedRHSA-2025:813226.05.2025
Red Hat Enterprise Linux 8.2 Advanced Update SupportlibsoupFixedRHSA-2025:848004.06.2025
Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update SupportlibsoupFixedRHSA-2025:866309.06.2025
Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update SupportlibsoupFixedRHSA-2025:848204.06.2025
Red Hat Enterprise Linux 8.6 Telecommunications Update ServicelibsoupFixedRHSA-2025:848204.06.2025
Red Hat Enterprise Linux 8.6 Update Services for SAP SolutionslibsoupFixedRHSA-2025:848204.06.2025

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-125
https://bugzilla.redhat.com/show_bug.cgi?id=2354669libsoup: Heap buffer over-read in `skip_insignificant_space` when sniffing content

7 High

CVSS3

Связанные уязвимости

CVSS3: 7
ubuntu
4 месяца назад

A flaw was found in libsoup. The package is vulnerable to a heap buffer over-read when sniffing content via the skip_insight_whitespace() function. Libsoup clients may read one byte out-of-bounds in response to a crafted HTTP response by an HTTP server.

CVSS3: 7
nvd
4 месяца назад

A flaw was found in libsoup. The package is vulnerable to a heap buffer over-read when sniffing content via the skip_insight_whitespace() function. Libsoup clients may read one byte out-of-bounds in response to a crafted HTTP response by an HTTP server.

CVSS3: 7
msrc
3 месяца назад

Описание отсутствует

CVSS3: 7
debian
4 месяца назад

A flaw was found in libsoup. The package is vulnerable to a heap buffe ...

CVSS3: 7
github
4 месяца назад

A flaw was found in libsoup. The package is vulnerable to a heap buffer over-read when sniffing content via the skip_insight_whitespace() function. Libsoup clients may read one byte out-of-bounds in response to a crafted HTTP response by an HTTP server.

7 High

CVSS3