MGASA-2025-0261

Source
https://advisories.mageia.org/MGASA-2025-0261.html
Import Source
https://advisories.mageia.org/MGASA-2025-0261.json
JSON Data
https://api.test.osv.dev/v1/vulns/MGASA-2025-0261
Related
Published
2025-11-05T22:49:51Z
Modified
2025-11-05T22:07:13Z
Summary
Updated libsoup3 & libsoup packages fix security vulnerabilities
Details

Libsoup: heap buffer over-read in skip_insignificant_space when sniffing content. (CVE-2025-2784) Libsoup: denial of service attack to websocket server. (CVE-2025-32049) Libsoup: integer overflow in appendparamquoted. (CVE-2025-32050) Libsoup: segmentation fault when parsing malformed data uri. (CVE-2025-32051) Libsoup: heap buffer overflow in sniffunknown(). (CVE-2025-32052) Libsoup: heap buffer overflows in snifffeedorhtml() and skipinsignificantspace(). (CVE-2025-32053) Libsoup: out of bounds reads in soupheadersparserequest(). (CVE-2025-32906) Libsoup: denial of service in server when client requests a large amount of overlapping ranges with range header. (CVE-2025-32907) Libsoup: denial of service on libsoup through http/2 server. (CVE-2025-32908) Libsoup: null pointer dereference on libsoup through function "sniffmp4" in soup-content-sniffer.c. (CVE-2025-32909) Libsoup: null pointer deference on libsoup via /auth/soup-auth-digest.c through "soupauthdigestauthenticate" on client when server omits the "realm" parameter in an unauthorized response with digest authentication. (CVE-2025-32910) Libsoup: double free on soupmessageheadersgetcontentdisposition() through "soup-message-headers.c" via "params" ghashtable value. (CVE-2025-32911) Libsoup: null pointer dereference in client when server omits the "nonce" parameter in an unauthorized response with digest authentication. (CVE-2025-32912) Libsoup: null pointer dereference in soupmessageheadersgetcontentdisposition when "filename" parameter is present, but has no value in content-disposition header. (CVE-2025-32913) Libsoup: oob read on libsoup through function "soupmultipartnewfrommessage" in soup-multipart.c leads to crash or exit of process. (CVE-2025-32914) Libsoup: memory leak on soupheaderparsequality_list() via soup-headers.c. (CVE-2025-46420) Libsoup: information disclosure may leads libsoup client sends authorization header to a different host when being redirected by a server. (CVE-2025-46421) Libsoup: null pointer dereference in libsoup may lead to denial of service. (CVE-2025-4476) Libsoup: integer overflow in cookie expiration date handling in libsoup. (CVE-2025-4945)

References
Credits

Affected packages

Mageia:9 / libsoup3

Package

Name
libsoup3
Purl
pkg:rpm/mageia/libsoup3?arch=source&distro=mageia-9

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
3.4.2-1.2.mga9

Ecosystem specific

{
    "section": "core"
}

Mageia:9 / libsoup

Package

Name
libsoup
Purl
pkg:rpm/mageia/libsoup?arch=source&distro=mageia-9

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
2.74.3-1.2.mga9

Ecosystem specific

{
    "section": "core"
}