GNOME libsoup
cpe:2.3:a:gnome:libsoup:*:*:*:*:*:*:*
- < 3.6.5
A heap buffer over-read vulnerability has been identified in the Libsoup HTTP library, specifically in versions prior to 3.6.5. The issue arises in the content sniffer's skip_insignificant_whitespace() function, where Libsoup clients can inadvertently read one byte out-of-bounds. This vulnerability can be triggered by a crafted HTTP response from an HTTP server.
Exploitation of this vulnerability leads to a heap buffer over-read, allowing for out-of-bounds memory access.
Users can apply the available update for Libsoup. Instructions for applying this update can be found on the Red Hat Customer Portal.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.