REDHAT-BUG-2359357: High severity libsoup vulnerability
Published Apr 14, 2025
·Updated
libsoup prior to 3.6.2 is vulnerable to a null pointer dereference in soupmessageheadersgetcontentdisposition() . A malicious HTTP peer may crash a libsoup client or server that uses this function.
Affected Software
1 affected component
libsoup libsoup<3.6.2
Event History
Apr 14, 2025
Data Sourced
via Red Hat·02:00 AM
DescriptionSeverityAffected Software
Frequently Asked Questions
1
What is the severity of REDHAT-BUG-2359357?
The severity of REDHAT-BUG-2359357 is high due to the potential for a crash of the libsoup client or server.
2
How do I fix REDHAT-BUG-2359357?
To fix REDHAT-BUG-2359357, upgrade libsoup to version 3.6.2 or later.
3
What causes REDHAT-BUG-2359357?
REDHAT-BUG-2359357 is caused by a null pointer dereference in the soup_message_headers_get_content_disposition() function.
4
Which versions of libsoup are affected by REDHAT-BUG-2359357?
Versions of libsoup prior to 3.6.2 are affected by REDHAT-BUG-2359357.
5
Can REDHAT-BUG-2359357 affect a server or client?
Yes, REDHAT-BUG-2359357 can affect both a libsoup client and server, leading to potential crashes.