Описание
A use-after-free type vulnerability was found in libsoup, in the soup_message_headers_get_content_disposition() function. This flaw allows a malicious HTTP client to cause memory corruption in the libsoup server.
Меры по смягчению последствий
Currently, no mitigation is available for this vulnerability.
Затронутые пакеты
Платформа | Пакет | Состояние | Рекомендация | Релиз |
---|---|---|---|---|
Red Hat Enterprise Linux 10 | libsoup3 | Not affected | ||
Red Hat Enterprise Linux 6 | libsoup | Out of support scope | ||
Red Hat Enterprise Linux 7 Extended Lifecycle Support | libsoup | Fixed | RHSA-2025:9179 | 17.06.2025 |
Red Hat Enterprise Linux 8 | libsoup | Fixed | RHSA-2025:4560 | 06.05.2025 |
Red Hat Enterprise Linux 8 | mingw-freetype | Fixed | RHSA-2025:8292 | 29.05.2025 |
Red Hat Enterprise Linux 8 | spice-client-win | Fixed | RHSA-2025:8292 | 29.05.2025 |
Red Hat Enterprise Linux 8 | libsoup | Fixed | RHSA-2025:4560 | 06.05.2025 |
Red Hat Enterprise Linux 8.2 Advanced Update Support | libsoup | Fixed | RHSA-2025:4538 | 06.05.2025 |
Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support | libsoup | Fixed | RHSA-2025:4609 | 07.05.2025 |
Red Hat Enterprise Linux 8.4 Telecommunications Update Service | libsoup | Fixed | RHSA-2025:4609 | 07.05.2025 |
Показывать по
Дополнительная информация
Статус:
EPSS
9 Critical
CVSS3
Связанные уязвимости
A use-after-free type vulnerability was found in libsoup, in the soup_message_headers_get_content_disposition() function. This flaw allows a malicious HTTP client to cause memory corruption in the libsoup server.
A use-after-free type vulnerability was found in libsoup, in the soup_message_headers_get_content_disposition() function. This flaw allows a malicious HTTP client to cause memory corruption in the libsoup server.
A use-after-free type vulnerability was found in libsoup, in the soup_ ...
A flaw was found in libsoup, which is vulnerable to a use-after-free memory issue not on the heap in the soup_message_headers_get_content_disposition() function. This flaw allows a malicious HTTP client to cause memory corruption in the libsoup server.
Уязвимость функции soup_message_headers_get_content_disposition() библиотеки libsoup графического интерфейса GNOME, позволяющая нарушителю выполнить произвольный код
EPSS
9 Critical
CVSS3