Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2025-32907

Опубликовано: 14 апр. 2025
Источник: ubuntu
Приоритет: medium
EPSS Низкий
CVSS3: 5.3

Описание

A flaw was found in libsoup. The implementation of HTTP range requests is vulnerable to a resource consumption attack. This flaw allows a malicious client to request the same range many times in a single HTTP request, causing the server to use large amounts of memory. This does not allow for a full denial of service.

РелизСтатусПримечание
devel

deferred

2025-06-04
esm-infra/bionic

deferred

2025-06-04
esm-infra/focal

deferred

2025-06-04
esm-infra/xenial

deferred

2025-06-04
focal

ignored

end of standard support, was needs-triage
jammy

deferred

2025-06-04
noble

deferred

2025-06-04
oracular

deferred

2025-06-04
plucky

deferred

2025-06-04
upstream

needed

Показывать по

РелизСтатусПримечание
devel

deferred

2025-06-04
esm-apps/jammy

deferred

2025-06-04
esm-infra/focal

DNE

focal

DNE

jammy

deferred

2025-06-04
noble

deferred

2025-06-04
oracular

deferred

2025-06-04
plucky

deferred

2025-06-04
upstream

released

3.6.4

Показывать по

EPSS

Процентиль: 32%
0.00117
Низкий

5.3 Medium

CVSS3

Связанные уязвимости

CVSS3: 5.3
redhat
2 месяца назад

A flaw was found in libsoup. The implementation of HTTP range requests is vulnerable to a resource consumption attack. This flaw allows a malicious client to request the same range many times in a single HTTP request, causing the server to use large amounts of memory. This does not allow for a full denial of service.

CVSS3: 5.3
nvd
2 месяца назад

A flaw was found in libsoup. The implementation of HTTP range requests is vulnerable to a resource consumption attack. This flaw allows a malicious client to request the same range many times in a single HTTP request, causing the server to use large amounts of memory. This does not allow for a full denial of service.

CVSS3: 5.3
debian
2 месяца назад

A flaw was found in libsoup. The implementation of HTTP range requests ...

CVSS3: 7.5
github
2 месяца назад

A flaw was found in libsoup. The implementation of HTTP range requests is vulnerable to a resource consumption attack. This flaw allows a malicious client to request the same range many times in a single HTTP request, causing the server to use large amounts of memory.

CVSS3: 7.5
fstec
7 месяцев назад

Уязвимость библиотеки libsoup графического интерфейса GNOME, связанная с асимметричным потреблением ресурсов, позволяющая нарушителю вызвать отказ в обслуживании

EPSS

Процентиль: 32%
0.00117
Низкий

5.3 Medium

CVSS3

Уязвимость CVE-2025-32907