Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2025-4945

Опубликовано: 19 мая 2025
Источник: ubuntu
Приоритет: medium
CVSS3: 3.7

Описание

A flaw was found in the cookie parsing logic of the libsoup HTTP library, used in GNOME applications and other software. The vulnerability arises when processing the expiration date of cookies, where a specially crafted value can trigger an integer overflow. This may result in undefined behavior, allowing an attacker to bypass cookie expiration logic, causing persistent or unintended cookie behavior. The issue stems from improper validation of large integer inputs during date arithmetic operations within the cookie parsing routines.

РелизСтатусПримечание
devel

deferred

2025-06-04
esm-infra/bionic

deferred

2025-06-04
esm-infra/focal

deferred

2025-06-04
esm-infra/xenial

deferred

2025-06-04
focal

ignored

end of standard support, was deferred [2025-06-04]
jammy

deferred

2025-06-04
noble

deferred

2025-06-04
oracular

deferred

2025-06-04
plucky

deferred

2025-06-04
upstream

deferred

2025-06-04

Показывать по

РелизСтатусПримечание
devel

deferred

2025-06-04
esm-apps/jammy

deferred

2025-06-04
esm-infra/focal

DNE

focal

DNE

jammy

deferred

2025-06-04
noble

deferred

2025-06-04
oracular

deferred

2025-06-04
plucky

deferred

2025-06-04
upstream

deferred

2025-06-04

Показывать по

3.7 Low

CVSS3

Связанные уязвимости

CVSS3: 3.7
redhat
около 1 месяца назад

A flaw was found in the cookie parsing logic of the libsoup HTTP library, used in GNOME applications and other software. The vulnerability arises when processing the expiration date of cookies, where a specially crafted value can trigger an integer overflow. This may result in undefined behavior, allowing an attacker to bypass cookie expiration logic, causing persistent or unintended cookie behavior. The issue stems from improper validation of large integer inputs during date arithmetic operations within the cookie parsing routines.

CVSS3: 3.7
nvd
около 1 месяца назад

A flaw was found in the cookie parsing logic of the libsoup HTTP library, used in GNOME applications and other software. The vulnerability arises when processing the expiration date of cookies, where a specially crafted value can trigger an integer overflow. This may result in undefined behavior, allowing an attacker to bypass cookie expiration logic, causing persistent or unintended cookie behavior. The issue stems from improper validation of large integer inputs during date arithmetic operations within the cookie parsing routines.

CVSS3: 3.7
debian
около 1 месяца назад

A flaw was found in the cookie parsing logic of the libsoup HTTP libra ...

CVSS3: 3.7
github
около 1 месяца назад

A flaw was found in the cookie parsing logic of the libsoup HTTP library, used in GNOME applications and other software. The vulnerability arises when processing the expiration date of cookies, where a specially crafted value can trigger an integer overflow. This may result in undefined behavior, allowing an attacker to bypass cookie expiration logic, causing persistent or unintended cookie behavior. The issue stems from improper validation of large integer inputs during date arithmetic operations within the cookie parsing routines.

3.7 Low

CVSS3