REDHAT-BUG-2357067: Integer Overflow
Published Apr 3, 2025
·Updated
libsoup's appendparamquoted() function, prior to libsoup 3.6.1, contains an integer overflow bug resulting in buffer under-read, which may be triggered by sending an extremely large HTTP request to the libsoup server.
Affected Software
1 affected component
Gnome libsoup<3.6.1
Event History
Apr 3, 2025
Data Sourced
via Red Hat·01:43 AM
DescriptionSeverityAffected Software
Frequently Asked Questions
1
What is the severity of REDHAT-BUG-2357067?
The severity of REDHAT-BUG-2357067 is high due to the potential for buffer under-read caused by an integer overflow.
2
How do I fix REDHAT-BUG-2357067?
To fix REDHAT-BUG-2357067, upgrade libsoup to version 3.6.1 or later.
3
What symptoms indicate the presence of REDHAT-BUG-2357067?
Symptoms of REDHAT-BUG-2357067 may include application crashes or abnormal behavior upon receiving large HTTP requests.
4
Which versions of libsoup are affected by REDHAT-BUG-2357067?
Versions of libsoup prior to 3.6.1 are affected by REDHAT-BUG-2357067.
5
What is the impact of exploiting REDHAT-BUG-2357067?
Exploiting REDHAT-BUG-2357067 can lead to potential denial of service or arbitrary code execution due to the buffer under-read.