CVE-2025-4476
EUVD-2025-1554016.05.2025, 18:16
A denial-of-service vulnerability has been identified in the libsoup HTTP client library. This flaw can be triggered when a libsoup client receives a 401 (Unauthorized) HTTP response containing a specifically crafted domain parameter within the WWW-Authenticate header. Processing this malformed header can lead to a crash of the client application using libsoup. An attacker could exploit this by setting up a malicious HTTP server. If a user's application using the vulnerable libsoup library connects to this malicious server, it could result in a denial-of-service. Successful exploitation requires tricking a user's client application into connecting to the attacker's malicious server.Enginsight
Awaiting analysis
This vulnerability is currently awaiting analysis.
Ubuntu Releases
Ubuntu Product | |||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| libsoup3 |
| ||||||||||||||||||
| libsoup2.4 |
|
openSUSE / SLES Releases
openSUSE Product | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| libsoup-2_4-1 |
| ||||||||||||||||||||||||
| libsoup-2_4-1-32bit |
| ||||||||||||||||||||||||
| libsoup-3_0-0 |
| ||||||||||||||||||||||||
| libsoup-devel |
| ||||||||||||||||||||||||
| libsoup-lang |
| ||||||||||||||||||||||||
| libsoup2-devel |
| ||||||||||||||||||||||||
| libsoup2-lang |
| ||||||||||||||||||||||||
| typelib-1_0-Soup-2_4 |
| ||||||||||||||||||||||||
| typelib-1_0-Soup-3_0 |
|
Common Weakness Enumeration