REDHAT-BUG-2325284: High severity libsoup vulnerability
GNOME libsoup before 3.6.0 allows HTTP request smuggling in some configurations because '\0' characters at the end of header names are ignored, i.e., a "Transfer-Encoding\0: chunked" header is treated the same as a "Transfer-Encoding: chunked" header.
Affected Software
Event History
Frequently Asked Questions
What is the severity of REDHAT-BUG-2325284?
REDHAT-BUG-2325284 is considered a medium severity vulnerability due to the potential for HTTP request smuggling.
How do I fix REDHAT-BUG-2325284?
To fix REDHAT-BUG-2325284, upgrade GNOME libsoup to version 3.6.0 or later.
What versions of GNOME libsoup are affected by REDHAT-BUG-2325284?
GNOME libsoup versions prior to 3.6.0 are affected by REDHAT-BUG-2325284.
What does REDHAT-BUG-2325284 exploit?
REDHAT-BUG-2325284 exploits the way '\0' characters in header names are handled, leading to HTTP request smuggling.
Is there a workaround for REDHAT-BUG-2325284?
There is no recommended workaround for REDHAT-BUG-2325284; the best course of action is to apply the patch by upgrading to the fixed version.