REDHAT-BUG-2357070: Medium severity libsoup vulnerability
Published Apr 3, 2025
·Updated
libsoup prior to version 3.6.1 is vulnerable to heap buffer over-reads in the content sniffer's snifffeedorhtml() and skipinsignificantspace() functions. libsoup clients may read out of bounds in response to a crafted HTTP response sent by an HTTP server.
Affected Software
1 affected component
Gnome libsoup<3.6.1
Event History
Apr 3, 2025
Data Sourced
via Red Hat·01:43 AM
DescriptionSeverityAffected Software
Frequently Asked Questions
1
What is the severity of REDHAT-BUG-2357070?
The severity of REDHAT-BUG-2357070 is considered high due to potential exploitation leading to heap buffer over-reads.
2
How do I fix REDHAT-BUG-2357070?
To fix REDHAT-BUG-2357070, upgrade libsoup to version 3.6.1 or later.
3
What versions of libsoup are affected by REDHAT-BUG-2357070?
Redhat-BUG-2357070 affects libsoup versions prior to 3.6.1.
4
What are the potential impacts of REDHAT-BUG-2357070?
Potential impacts of REDHAT-BUG-2357070 include reading out of bounds due to crafted HTTP responses.
5
Who is impacted by REDHAT-BUG-2357070?
Clients using libsoup versions prior to 3.6.1 may be impacted by REDHAT-BUG-2357070.