REDHAT-BUG-2359355: High severity libsoup vulnerability
Published Apr 14, 2025
·Updated
libsoup prior to version 3.6.3 is vulnerable to a free of memory not on the heap in soupmessageheadersgetcontentdisposition(). A malicious HTTP client may induce memory corruption in the libsoup server.
Affected Software
1 affected component
libsoup libsoup<3.6.3
Event History
Apr 14, 2025
Data Sourced
via Red Hat·02:00 AM
DescriptionSeverityAffected Software
Frequently Asked Questions
1
What is the severity of REDHAT-BUG-2359355?
The severity of REDHAT-BUG-2359355 is critical due to the potential for memory corruption.
2
How do I fix REDHAT-BUG-2359355?
To fix REDHAT-BUG-2359355, upgrade libsoup to version 3.6.3 or later.
3
What is impacted by REDHAT-BUG-2359355?
REDHAT-BUG-2359355 affects libsoup versions earlier than 3.6.3.
4
What kind of vulnerability is REDHAT-BUG-2359355?
REDHAT-BUG-2359355 is a memory corruption vulnerability caused by improper handling of HTTP headers.
5
Who can exploit REDHAT-BUG-2359355?
A malicious HTTP client can exploit REDHAT-BUG-2359355 to cause issues in the libsoup server.