Description
GNOME libsoup before 3.6.1 allows a buffer overflow in applications that perform conversion to UTF-8 in soup_header_parse_param_list_strict. There is a plausible way to reach this remotely via soup_message_headers_get_content_type (e.g., an application may want to retrieve the content type of a request or response).
CVSS breakdown
CVSS 3.1
Attack Vector
Network
Attack Complexity
High
Privileges Required
None
User Interaction
None
Scope
Changed
Confidentiality
Low
Integrity
Low
Availability
Low
Affected products
- GNOME / libsoup0 – 3.6.1
References
- MISChttps://gitlab.gnome.org/Teams/Releng/security/-/wikis/home
- MISChttps://gitlab.gnome.org/GNOME/libsoup/-/merge_requests/407
- MISChttps://gitlab.gnome.org/GNOME/libsoup/-/merge_requests/407#note_2316401
- MISChttps://offsec.almond.consulting/using-aflplusplus-on-bug-bounty-programs-an-example-with-gnome-libsoup.html
Updated 9m ago · 8 sources