CVE-2011-2524

EUVD-2011-2509
Directory traversal vulnerability in soup-uri.c in SoupServer in libsoup before 2.35.4 allows remote attackers to read arbitrary files via a %2e%2e (encoded dot dot) in a URI.
Path Traversal
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
5 UNKNOWN
NETWORK
LOW
AV:N/AC:L/Au:N/C:P/I:N/A:N
Base Score
CVSS 3.x
EPSS Score
Percentile: 69%
Affected Products (NVD)
VendorProductVersion
gnomelibsoup
𝑥
≤ 2.35.3
gnomelibsoup
2.0
gnomelibsoup
2.2
gnomelibsoup
2.2.0
gnomelibsoup
2.2.1
gnomelibsoup
2.2.2
gnomelibsoup
2.2.3
gnomelibsoup
2.2.4
gnomelibsoup
2.2.5
gnomelibsoup
2.2.6
gnomelibsoup
2.2.6.1
gnomelibsoup
2.2.7
gnomelibsoup
2.2.91
gnomelibsoup
2.2.92
gnomelibsoup
2.2.93
gnomelibsoup
2.2.94
gnomelibsoup
2.2.95.1
gnomelibsoup
2.2.96
gnomelibsoup
2.2.97
gnomelibsoup
2.2.98
gnomelibsoup
2.2.99
gnomelibsoup
2.2.100
gnomelibsoup
2.2.101
gnomelibsoup
2.2.102
gnomelibsoup
2.2.103
gnomelibsoup
2.2.104
gnomelibsoup
2.3.0.1
gnomelibsoup
2.3.2
gnomelibsoup
2.3.4
gnomelibsoup
2.4.0
gnomelibsoup
2.4.1
gnomelibsoup
2.23.1
gnomelibsoup
2.23.6
gnomelibsoup
2.23.91
gnomelibsoup
2.23.92
gnomelibsoup
2.24.0.1
gnomelibsoup
2.24.1
gnomelibsoup
2.25.2
gnomelibsoup
2.25.3
gnomelibsoup
2.25.4
gnomelibsoup
2.25.5
gnomelibsoup
2.25.91
gnomelibsoup
2.26.0
gnomelibsoup
2.26.1
gnomelibsoup
2.27.1
gnomelibsoup
2.27.2
gnomelibsoup
2.27.4
gnomelibsoup
2.27.5
gnomelibsoup
2.27.90
gnomelibsoup
2.27.91
gnomelibsoup
2.27.92
gnomelibsoup
2.28.0
gnomelibsoup
2.28.1
gnomelibsoup
2.29.3
gnomelibsoup
2.29.5
gnomelibsoup
2.29.6
gnomelibsoup
2.29.90
gnomelibsoup
2.29.91
gnomelibsoup
2.30.0
gnomelibsoup
2.30.1
gnomelibsoup
2.31.2
gnomelibsoup
2.31.6
gnomelibsoup
2.31.90
gnomelibsoup
2.31.92
gnomelibsoup
2.32.0
gnomelibsoup
2.32.1
gnomelibsoup
2.32.2
gnomelibsoup
2.33.4
gnomelibsoup
2.33.5
gnomelibsoup
2.33.6
gnomelibsoup
2.33.90
gnomelibsoup
2.33.92
gnomelibsoup
2.34.0
gnomelibsoup
2.34.1
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
libsoup2.4
bookworm
2.74.3-1
fixed
bullseye
2.72.0-2
fixed
sid
2.74.3-8
fixed
trixie
2.74.3-8
fixed
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
libsoup
hardy
ignored
lucid
dne
maverick
dne
natty
dne
libsoup2.4
hardy
ignored
lucid
Fixed 2.30.2-0ubuntu0.2
released
maverick
Fixed 2.31.92-0ubuntu1.1
released
natty
Fixed 2.34.0-0ubuntu1.1
released