Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2025-4969

Опубликовано: 21 мая 2025
Источник: ubuntu
Приоритет: medium
CVSS3: 6.5

Описание

A vulnerability was found in the libsoup package. This flaw stems from its failure to correctly verify the termination of multipart HTTP messages. This can allow a remote attacker to send a specially crafted multipart HTTP body, causing the libsoup-consuming server to read beyond its allocated memory boundaries (out-of-bounds read).

РелизСтатусПримечание
devel

deferred

2025-05-22
esm-infra/bionic

deferred

2025-05-22
esm-infra/focal

deferred

2025-05-22
esm-infra/xenial

deferred

2025-05-22
focal

ignored

end of standard support, was deferred [2025-05-22]
jammy

deferred

2025-05-22
noble

deferred

2025-05-22
oracular

deferred

2025-05-22
plucky

deferred

2025-05-22
upstream

deferred

2025-05-22

Показывать по

РелизСтатусПримечание
devel

deferred

2025-05-22
esm-apps/jammy

deferred

2025-05-22
esm-infra/focal

DNE

focal

DNE

jammy

deferred

2025-05-22
noble

deferred

2025-05-22
oracular

deferred

2025-05-22
plucky

deferred

2025-05-22
upstream

deferred

2025-05-22

Показывать по

6.5 Medium

CVSS3

Связанные уязвимости

CVSS3: 6.5
redhat
около 1 месяца назад

A vulnerability was found in the libsoup package. This flaw stems from its failure to correctly verify the termination of multipart HTTP messages. This can allow a remote attacker to send a specially crafted multipart HTTP body, causing the libsoup-consuming server to read beyond its allocated memory boundaries (out-of-bounds read).

CVSS3: 6.5
nvd
29 дней назад

A vulnerability was found in the libsoup package. This flaw stems from its failure to correctly verify the termination of multipart HTTP messages. This can allow a remote attacker to send a specially crafted multipart HTTP body, causing the libsoup-consuming server to read beyond its allocated memory boundaries (out-of-bounds read).

CVSS3: 6.5
debian
29 дней назад

A vulnerability was found in the libsoup package. This flaw stems from ...

CVSS3: 6.5
github
28 дней назад

A vulnerability was found in the libsoup package. This flaw stems from its failure to correctly verify the termination of multipart HTTP messages. This can allow a remote attacker to send a specially crafted multipart HTTP body, causing the libsoup-consuming server to read beyond its allocated memory boundaries (out-of-bounds read).

suse-cvrf
14 дней назад

Security update for libsoup

6.5 Medium

CVSS3