Описание
A flaw was found in libsoup, an HTTP client/server library. This HTTP Request Smuggling vulnerability arises from non-RFC-compliant parsing in the soup_filter_input_stream_read_line() logic, where libsoup accepts malformed chunk headers, such as lone line feed (LF) characters instead of the required carriage return and line feed (CRLF). A remote attacker can exploit this without authentication or user interaction by sending specially crafted chunked requests. This allows libsoup to parse and process multiple HTTP requests from a single network message, potentially leading to information disclosure.
| Релиз | Статус | Примечание |
|---|---|---|
| devel | needs-triage | |
| esm-apps/resolute | released | 2.74.3-10.1ubuntu5+esm2 |
| esm-infra-legacy/xenial | released | 2.52.2-1ubuntu0.3+esm7 |
| esm-infra/bionic | released | 2.62.1-1ubuntu0.4+esm8 |
| esm-infra/focal | released | 2.70.0-1ubuntu0.5+esm3 |
| esm-infra/xenial | ignored | end of ESM support, was needs-triage |
| jammy | released | 2.74.2-3ubuntu0.8 |
| noble | released | 2.74.3-6ubuntu1.8 |
| questing | ignored | end of life, was needs-triage |
| resolute | needed |
Показывать по
| Релиз | Статус | Примечание |
|---|---|---|
| devel | not-affected | 3.6.6-1 |
| esm-apps/jammy | released | 3.0.7-0ubuntu1+esm8 |
| jammy | needed | |
| noble | released | 3.4.4-5ubuntu0.8 |
| questing | ignored | end of life, was needs-triage |
| resolute | not-affected | 3.6.6-1 |
| upstream | released | 3.6.5-8 |
Показывать по
EPSS
5.3 Medium
CVSS3
Связанные уязвимости
A flaw was found in libsoup, an HTTP client/server library. This HTTP Request Smuggling vulnerability arises from non-RFC-compliant parsing in the soup_filter_input_stream_read_line() logic, where libsoup accepts malformed chunk headers, such as lone line feed (LF) characters instead of the required carriage return and line feed (CRLF). A remote attacker can exploit this without authentication or user interaction by sending specially crafted chunked requests. This allows libsoup to parse and process multiple HTTP requests from a single network message, potentially leading to information disclosure.
A flaw was found in libsoup, an HTTP client/server library. This HTTP Request Smuggling vulnerability arises from non-RFC-compliant parsing in the soup_filter_input_stream_read_line() logic, where libsoup accepts malformed chunk headers, such as lone line feed (LF) characters instead of the required carriage return and line feed (CRLF). A remote attacker can exploit this without authentication or user interaction by sending specially crafted chunked requests. This allows libsoup to parse and process multiple HTTP requests from a single network message, potentially leading to information disclosure.
A flaw was found in libsoup, an HTTP client/server library. This HTTP ...
EPSS
5.3 Medium
CVSS3