Out-of-bounds Read Affecting libsoup package, versions [,2.66.4)[2.68.0, 2.68.2)


Severity

Recommended
0.0
critical
0
10

CVSS assessment made by Snyk's Security Team. Learn more

Threat Intelligence

EPSS
0.55% (78th percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk IDSNYK-UNMANAGED-LIBSOUP-2368715
  • published26 Jan 2022
  • disclosed6 Oct 2019
  • creditUnknown

Introduced: 6 Oct 2019

CVE-2019-17266  (opens in a new tab)
CWE-125  (opens in a new tab)

How to fix?

Upgrade libsoup to version 2.66.4, 2.68.2 or higher.

Overview

Affected versions of this package are vulnerable to Out-of-bounds Read libsoup from versions 2.65.1 until 2.68.1 have a heap-based buffer over-read because soup_ntlm_parse_challenge() in soup-auth-ntlm.c does not properly check an NTLM message's length before proceeding with a memcpy.

References

CVSS Scores

version 3.1