Back

CRITICAL

libsoup: Stack based buffer overflow with HTTP Chunked Encoding

Published Apr 24, 2018

Description

An exploitable stack based buffer overflow vulnerability exists in the GNOME libsoup 2.58. A specially crafted HTTP request can cause a stack overflow resulting in remote code execution. An attacker can send a special HTTP request to the vulnerable server to trigger this vulnerability.

Affected products

Remediation

Red Hat statement

This issue affects the libsoup packages as shipped with Red Hat Enterprise Linux 7. However, these packages have been compiled with additional security mitigation techniques ("stack smashing protection"), which makes exploitation significantly harder. Thus, in most cases an exploitation attempt should be mitigated to a mere crash. However, successful exploitation to execute arbitrary code can't be ruled out entirely.

Metrics

References (10)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner talos
Published Apr 24, 2018
Updated Sep 17, 2024
Reserved Dec 1, 2016
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity Important
Public date Aug 10, 2017