ΠΠΏΠΈΡΠ°Π½ΠΈΠ΅
A flaw was found in libsoup. The implementation of HTTP range requests is vulnerable to a resource consumption attack. This flaw allows a malicious client to request the same range many times in a single HTTP request, causing the server to use large amounts of memory. This does not allow for a full denial of service.
| Π Π΅Π»ΠΈΠ· | Π‘ΡΠ°ΡΡΡ | ΠΡΠΈΠΌΠ΅ΡΠ°Π½ΠΈΠ΅ |
|---|---|---|
| devel | released | 2.74.3-10.1ubuntu4 |
| esm-apps/resolute | released | 2.74.3-10.1ubuntu4 |
| esm-infra-legacy/xenial | released | 2.52.2-1ubuntu0.3+esm5 |
| esm-infra/bionic | released | 2.62.1-1ubuntu0.4+esm6 |
| esm-infra/focal | released | 2.70.0-1ubuntu0.5+esm1 |
| esm-infra/xenial | released | 2.52.2-1ubuntu0.3+esm5 |
| focal | ignored | end of standard support, was needs-triage |
| jammy | released | 2.74.2-3ubuntu0.6 |
| noble | released | 2.74.3-6ubuntu1.6 |
| oracular | ignored | end of life, was needs-triage |
ΠΠΎΠΊΠ°Π·ΡΠ²Π°ΡΡ ΠΏΠΎ
| Π Π΅Π»ΠΈΠ· | Π‘ΡΠ°ΡΡΡ | ΠΡΠΈΠΌΠ΅ΡΠ°Π½ΠΈΠ΅ |
|---|---|---|
| devel | released | 3.6.5-3 |
| esm-apps/jammy | released | 3.0.7-0ubuntu1+esm5 |
| esm-infra/focal | DNE | |
| focal | DNE | |
| jammy | needed | |
| noble | released | 3.4.4-5ubuntu0.5 |
| oracular | ignored | end of life, was needs-triage |
| plucky | released | 3.6.5-1ubuntu0.2 |
| questing | released | 3.6.5-3 |
| resolute | released | 3.6.5-3 |
ΠΠΎΠΊΠ°Π·ΡΠ²Π°ΡΡ ΠΏΠΎ
EPSS
5.3 Medium
CVSS3
Π‘Π²ΡΠ·Π°Π½Π½ΡΠ΅ ΡΡΠ·Π²ΠΈΠΌΠΎΡΡΠΈ
A flaw was found in libsoup. The implementation of HTTP range requests is vulnerable to a resource consumption attack. This flaw allows a malicious client to request the same range many times in a single HTTP request, causing the server to use large amounts of memory. This does not allow for a full denial of service.
A flaw was found in libsoup. The implementation of HTTP range requests is vulnerable to a resource consumption attack. This flaw allows a malicious client to request the same range many times in a single HTTP request, causing the server to use large amounts of memory. This does not allow for a full denial of service.
Libsoup: denial of service in server when client requests a large amount of overlapping ranges with range header
A flaw was found in libsoup. The implementation of HTTP range requests ...
A flaw was found in libsoup. The implementation of HTTP range requests is vulnerable to a resource consumption attack. This flaw allows a malicious client to request the same range many times in a single HTTP request, causing the server to use large amounts of memory.
EPSS
5.3 Medium
CVSS3