REDHAT-BUG-2357069: Medium severity libsoup vulnerability
libsoup prior to version 3.6.1 is vulnerable to a heap buffer over-read in the content sniffer's sniffunknown() function. libsoup clients may read out of bounds in response to a crafted HTTP response sent by an HTTP server.
Affected Software
Event History
Frequently Asked Questions
What is the severity of REDHAT-BUG-2357069?
The vulnerability REDHAT-BUG-2357069 is classified as a moderate severity issue due to the potential for heap buffer over-reads.
How do I fix REDHAT-BUG-2357069?
To fix REDHAT-BUG-2357069, upgrade libsoup to version 3.6.1 or later.
What is the impact of REDHAT-BUG-2357069 on applications using libsoup?
Applications using libsoup prior to version 3.6.1 may be at risk of reading out-of-bounds data which can lead to unexpected behavior or security issues.
Are there any workarounds for REDHAT-BUG-2357069?
There are no known workarounds for REDHAT-BUG-2357069; the best solution is to upgrade to the patched version.
Who is affected by REDHAT-BUG-2357069?
Any user or application utilizing libsoup versions prior to 3.6.1 is affected by REDHAT-BUG-2357069.