REDHAT-BUG-2357068: Medium severity libsoup vulnerability
Published Apr 3, 2025
·Updated
libsoup's soupuridecodedatauri() function, prior to libsoup 3.6.1, may crash when processing a malformed data URI, resulting in denial of service.
Affected Software
1 affected component
Gnome libsoup<3.6.1
Event History
Apr 3, 2025
Data Sourced
via Red Hat·01:43 AM
DescriptionSeverityAffected Software
Frequently Asked Questions
1
What is the severity of REDHAT-BUG-2357068?
The severity of REDHAT-BUG-2357068 is categorized as denial of service due to potential crashes.
2
How do I fix REDHAT-BUG-2357068?
To fix REDHAT-BUG-2357068, you should upgrade to libsoup version 3.6.1 or later.
3
What causes the crash in REDHAT-BUG-2357068?
The crash in REDHAT-BUG-2357068 is caused by the handling of malformed data URIs in the soup_uri_decode_data_uri() function.
4
Which versions of libsoup are affected by REDHAT-BUG-2357068?
Versions of libsoup prior to 3.6.1 are affected by REDHAT-BUG-2357068.
5
What software uses libsoup related to REDHAT-BUG-2357068?
The affected software related to REDHAT-BUG-2357068 is GNOME's libsoup library.