PT-2018-2300 · Gnome+4 · Libsoup+4

Published

2018-06-29

·

Updated

2024-06-15

·

CVE-2018-12910

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions libsoup version 2.63.2
Description The issue is related to errors in input data processing in the get cookies function of the libsoup HTTP library. It may allow a remote attacker to execute arbitrary code using an empty hostname.
Recommendations For libsoup version 2.63.2, consider restricting the use of the get cookies function until a patch is available to prevent potential exploitation. Avoid using empty hostnames in the affected function to minimize the risk of arbitrary code execution. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

RCE

Out of bounds Read

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2019-00429
CESA-2018_3140
CVE-2018-12910
DLA-1416-1
DSA-4241-1
MGASA-2018-0328
OPENSUSE-SU-2018_2296-1
OPENSUSE-SU-2019:1310-1
OPENSUSE-SU-2019_1310-1
OPENSUSE-SU-2024:10994-1
RHSA-2018:3140
RHSA-2018_3140
SUSE-SU-2018:2204-1
SUSE-SU-2018:2204-2
USN-3701-1

Affected Products

Centos
Red Hat
Suse
Ubuntu
Libsoup