REDHAT-BUG-2354669: Medium severity libsoup vulnerability
Published Mar 25, 2025
·Updated
libsoup prior to version 3.6.5 is vulnerable to a heap buffer over-read in the content sniffer's skipinsignificantwhitespace() function. libsoup clients may read one byte out of bounds in response to a crafted HTTP response sent by an HTTP server.
Affected Software
1 affected component
Gnome libsoup<3.6.5
Event History
Mar 25, 2025
Data Sourced
via Red Hat·02:06 AM
DescriptionSeverityAffected Software
Frequently Asked Questions
1
What is the severity of REDHAT-BUG-2354669?
The severity of REDHAT-BUG-2354669 is considered to be high due to the potential for a heap buffer over-read.
2
How do I fix REDHAT-BUG-2354669?
To fix REDHAT-BUG-2354669, you should update libsoup to version 3.6.5 or later.
3
Who is affected by REDHAT-BUG-2354669?
Clients using libsoup versions prior to 3.6.5 are affected by REDHAT-BUG-2354669.
4
What type of vulnerability is REDHAT-BUG-2354669?
REDHAT-BUG-2354669 is classified as a heap buffer over-read vulnerability.
5
What might happen if REDHAT-BUG-2354669 is exploited?
If exploited, REDHAT-BUG-2354669 may allow an attacker to read one byte out of bounds from a crafted HTTP response.