Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2025-32906

Опубликовано: 14 апр. 2025
Источник: redhat
CVSS3: 7.5
EPSS Низкий

Описание

A flaw was found in libsoup, where the soup_headers_parse_request() function may be vulnerable to an out-of-bound read. This flaw allows a malicious user to use a specially crafted HTTP request to crash the HTTP server.

Меры по смягчению последствий

Currently, no mitigation was found for this vulnerability.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 6libsoupOut of support scope
Red Hat Enterprise Linux 7libsoupAffected
Red Hat Enterprise Linux 10libsoup3FixedRHSA-2025:750513.05.2025
Red Hat Enterprise Linux 8libsoupFixedRHSA-2025:456006.05.2025
Red Hat Enterprise Linux 8mingw-freetypeFixedRHSA-2025:829229.05.2025
Red Hat Enterprise Linux 8spice-client-winFixedRHSA-2025:829229.05.2025
Red Hat Enterprise Linux 8libsoupFixedRHSA-2025:456006.05.2025
Red Hat Enterprise Linux 8.2 Advanced Update SupportlibsoupFixedRHSA-2025:453806.05.2025
Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update SupportlibsoupFixedRHSA-2025:460907.05.2025
Red Hat Enterprise Linux 8.4 Telecommunications Update ServicelibsoupFixedRHSA-2025:460907.05.2025

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-125
https://bugzilla.redhat.com/show_bug.cgi?id=2359341libsoup: Out of bounds reads in soup_headers_parse_request()

EPSS

Процентиль: 77%
0.0105
Низкий

7.5 High

CVSS3

Связанные уязвимости

CVSS3: 7.5
ubuntu
2 месяца назад

A flaw was found in libsoup, where the soup_headers_parse_request() function may be vulnerable to an out-of-bound read. This flaw allows a malicious user to use a specially crafted HTTP request to crash the HTTP server.

CVSS3: 7.5
nvd
2 месяца назад

A flaw was found in libsoup, where the soup_headers_parse_request() function may be vulnerable to an out-of-bound read. This flaw allows a malicious user to use a specially crafted HTTP request to crash the HTTP server.

CVSS3: 7.5
msrc
около 2 месяцев назад

Описание отсутствует

CVSS3: 7.5
debian
2 месяца назад

A flaw was found in libsoup, where the soup_headers_parse_request() fu ...

CVSS3: 7.5
github
2 месяца назад

A flaw was found in libsoup, where the soup_headers_parse_request() function may be vulnerable to an out-of-bound read. This flaw allows a malicious user to use a specially crafted HTTP request to crash the HTTP server.

EPSS

Процентиль: 77%
0.0105
Низкий

7.5 High

CVSS3