V
Scaner-VS
HomeCatalogSourcesCWECAPECATT&CKMitigationsProductsVendorsDocs
CVE-2025-4969
AST
Medium

A vulnerability was found in the libsoup package. This flaw stems from its failure to correctly verify the termination of multipart HTTP me…

CVSS
6.5
Medium
EPSS
0.01
p49
Published
2025-01-01
Updated
2025-01-01
Description

A vulnerability was found in the libsoup package. This flaw stems from its failure to correctly verify the termination of multipart HTTP messages. This can allow a remote attacker to send a specially crafted multipart HTTP body, causing the libsoup-consuming server to read beyond its allocated memory boundaries (out-of-bounds read).

Tags · CWE
RCEPre-auth
CWE-125
CAPEC-540
Affected products
Libsoup2.4Libsoup2.4Libsoup2.4Libsoup2.4Libsoup2.4Libsoup2.4Libsoup2.4Libsoup2.4Libsoup2.4Libsoup2.4Libsoup2.4Libsoup3Libsoup3Libsoup3Libsoup3Libsoup3Libsoup3Libsoup3
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L
Timeline
2025-01-01
Published
2025-01-01
Updated
CVSS 3.1 breakdown
Attack Vector
AV: N
Network (N)
Attack Complexity
AC: L
Low (L)
Privileges Required
PR: N
None (N)
User Interaction
UI: N
None (N)
Scope
S: U
Unchanged (U)
Confidentiality Impact
C: L
Low (L)
Integrity Impact
I: N
None (N)
Availability Impact
A: L
Low (L)
Exploit indicators
EPSS
0.007 · p49
Known exploited (KEV)
No
Known exploits — Сканер-ВС
No Сканер-ВС checks registered for this vulnerability yet.
Affected products
ProductVendorStatus
libsoup2.4Tracked
libsoup2.4Tracked
libsoup2.4Tracked
libsoup2.4Tracked
libsoup2.4Tracked
libsoup2.4Tracked
libsoup2.4Tracked
libsoup2.4Tracked
libsoup2.4Tracked
libsoup2.4Tracked
libsoup2.4Tracked
libsoup3Tracked
libsoup3Tracked
libsoup3Tracked
libsoup3Tracked
libsoup3Tracked
libsoup3Tracked
libsoup3Tracked
Source databases
AST
DEB
UBU
Related vulnerabilities