libsoup
cpe:2.3:a:gnome:libsoup:*:*:*:*:*:*:*
- < 3.6.2
A NULL pointer dereference vulnerability has been identified in libsoup, specifically in the 'soup_message_headers_get_content_disposition()' function. This vulnerability exists in libsoup versions prior to 3.6.2. When the 'filename' parameter is present but lacks a value in the Content-Disposition header, it can lead to a crash of the libsoup client or server utilizing this function. The issue allows a malicious HTTP peer to cause the crash.
Exploitation of this vulnerability leads to a crash of the libsoup client or server, causing a denial-of-service condition.
Users can apply the available update for libsoup. Instructions for applying this update can be found on the Red Hat Customer Portal.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.