PT-2007-1006 · Gnome · Libsoup
Josselin Mouette
+1
·
Publicado
2007-01-16
·
Atualizado
2024-06-15
·
CVE-2006-5876
CVSS v2.0
7.8
Alta
| Vetor | AV:N/AC:L/Au:N/C:N/I:N/A:C |
Name of the Vulnerable Software and Affected Versions:
libsoup HTTP library versions prior to 2.2.99
Description:
The issue allows remote attackers to cause a denial of service, potentially leading to disruption of protected information. This can be achieved through the exploitation of malformed HTTP headers, likely involving missing fields or values. The
soup headers parse function in soup-headers.c is specifically affected.Recommendations:
For versions prior to 2.2.99, update to version 2.2.99 or later to resolve the issue. As a temporary workaround, consider restricting access to the
soup headers parse function until a patch is available.Correção
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Libsoup