REDHAT-BUG-2458479: Medium severity Gnome libsoup vulnerability
HTTP Request Smuggling on libsoup through libsoup/http1/soup-body-input-stream.c:soupbodyinputstreamreadchunked() via Unsigned to Signed Conversion Error in chunk size
Requirements to exploit: spend malicious HTTP request to libsoup backend server operating behind non-libsoup proxy server, or to libsoup proxy server operating in front of non-libsoup backend server
Affected Software
Event History
Frequently Asked Questions
What is the severity of REDHAT-BUG-2458479?
The severity of REDHAT-BUG-2458479 is medium with a score of 4.
How do I fix REDHAT-BUG-2458479?
Fix REDHAT-BUG-2458479 by updating the Gnome libsoup library to the latest version that addresses this vulnerability.
What type of vulnerability is REDHAT-BUG-2458479?
REDHAT-BUG-2458479 is an HTTP Request Smuggling vulnerability.
What is required to exploit REDHAT-BUG-2458479?
Exploitation of REDHAT-BUG-2458479 requires sending a malicious HTTP request to a libsoup backend server operating behind a non-libsoup proxy.
Which software is affected by REDHAT-BUG-2458479?
The affected software for REDHAT-BUG-2458479 is Gnome libsoup.