REDHAT-BUG-2359356: Medium severity libsoup vulnerability
Published Apr 14, 2025
·Updated
libsoup prior to 3.6.5 is vulnerable to a null pointer dereference in SoupAuthDigest. A malicious HTTP server may cause the libsoup client to crash.
Affected Software
1 affected component
Gnome libsoup<3.6.5
Event History
Apr 14, 2025
Data Sourced
via Red Hat·02:00 AM
DescriptionSeverityAffected Software
Frequently Asked Questions
1
What is the severity of REDHAT-BUG-2359356?
The severity of REDHAT-BUG-2359356 is considered moderate due to the potential for a crash of the libsoup client.
2
How do I fix REDHAT-BUG-2359356?
To fix REDHAT-BUG-2359356, update libsoup to version 3.6.5 or later.
3
What causes the vulnerability in REDHAT-BUG-2359356?
The vulnerability in REDHAT-BUG-2359356 is caused by a null pointer dereference in SoupAuthDigest.
4
What software is affected by REDHAT-BUG-2359356?
The software affected by REDHAT-BUG-2359356 is libsoup versions prior to 3.6.5.
5
Can REDHAT-BUG-2359356 be exploited remotely?
Yes, REDHAT-BUG-2359356 can be exploited remotely by a malicious HTTP server.