REDHAT-BUG-2366513: Null Pointer Dereference
libsoup is vulnerable to a null pointer dereference in the soupauthdigestgetprotectionspace() function. An HTTP server may crash the libsoup client by responding with a 401 Unauthorized response in combination with a crafted domain parameter in the WWW-Authenticate header.
Affected Software
Event History
Frequently Asked Questions
What is the severity of REDHAT-BUG-2366513?
The severity of REDHAT-BUG-2366513 is categorized as high due to the potential for denial of service.
How do I fix REDHAT-BUG-2366513?
To fix REDHAT-BUG-2366513, upgrade to the latest version of libsoup that addresses this null pointer dereference vulnerability.
What systems are affected by REDHAT-BUG-2366513?
REDHAT-BUG-2366513 affects systems that utilize the libsoup library within GNOME software.
What causes REDHAT-BUG-2366513?
REDHAT-BUG-2366513 is caused by a null pointer dereference when libsoup handles certain HTTP 401 Unauthorized responses with a crafted domain parameter.
What impact does REDHAT-BUG-2366513 have on applications?
Applications using libsoup may crash if an HTTP server responds with a 401 Unauthorized status along with a specially crafted WWW-Authenticate header.