fkie_cve-2025-32907
Vulnerability from fkie_nvd
Published
2025-04-14 14:15
Modified
2025-05-29 07:15
Severity ?
Summary
A flaw was found in libsoup. The implementation of HTTP range requests is vulnerable to a resource consumption attack. This flaw allows a malicious client to request the same range many times in a single HTTP request, causing the server to use large amounts of memory. This does not allow for a full denial of service.
References
Impacted products
Vendor | Product | Version |
---|
{ "cveTags": [], "descriptions": [ { "lang": "en", "value": "A flaw was found in libsoup. The implementation of HTTP range requests is vulnerable to a resource consumption attack. This flaw allows a malicious client to request the same range many times in a single HTTP request, causing the server to use large amounts of memory. This does not allow for a full denial of service." }, { "lang": "es", "value": "Se encontr\u00f3 una falla en libsoup. La implementaci\u00f3n de solicitudes de rango HTTP es vulnerable a un ataque de consumo de recursos. Esta falla permite que un cliente malicioso solicite el mismo rango varias veces en una sola solicitud HTTP, lo que provoca que el servidor utilice grandes cantidades de memoria." } ], "id": "CVE-2025-32907", "lastModified": "2025-05-29T07:15:24.333", "metrics": { "cvssMetricV31": [ { "cvssData": { "attackComplexity": "LOW", "attackVector": "NETWORK", "availabilityImpact": "LOW", "baseScore": 5.3, "baseSeverity": "MEDIUM", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "privilegesRequired": "NONE", "scope": "UNCHANGED", "userInteraction": "NONE", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L", "version": "3.1" }, "exploitabilityScore": 3.9, "impactScore": 1.4, "source": "secalert@redhat.com", "type": "Secondary" } ] }, "published": "2025-04-14T14:15:24.580", "references": [ { "source": "secalert@redhat.com", "url": "https://access.redhat.com/errata/RHSA-2025:4439" }, { "source": "secalert@redhat.com", "url": "https://access.redhat.com/errata/RHSA-2025:4440" }, { "source": "secalert@redhat.com", "url": "https://access.redhat.com/errata/RHSA-2025:4508" }, { "source": "secalert@redhat.com", "url": "https://access.redhat.com/errata/RHSA-2025:7436" }, { "source": "secalert@redhat.com", "url": "https://access.redhat.com/errata/RHSA-2025:8128" }, { "source": "secalert@redhat.com", "url": "https://access.redhat.com/errata/RHSA-2025:8292" }, { "source": "secalert@redhat.com", "url": "https://access.redhat.com/security/cve/CVE-2025-32907" }, { "source": "secalert@redhat.com", "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2359342" } ], "sourceIdentifier": "secalert@redhat.com", "vulnStatus": "Awaiting Analysis", "weaknesses": [ { "description": [ { "lang": "en", "value": "CWE-1050" } ], "source": "secalert@redhat.com", "type": "Secondary" } ] }
Loading…
Loading…
Sightings
Author | Source | Type | Date |
---|
Nomenclature
- Seen: The vulnerability was mentioned, discussed, or seen somewhere by the user.
- Confirmed: The vulnerability is confirmed from an analyst perspective.
- Exploited: This vulnerability was exploited and seen by the user reporting the sighting.
- Patched: This vulnerability was successfully patched by the user reporting the sighting.
- Not exploited: This vulnerability was not exploited or seen by the user reporting the sighting.
- Not confirmed: The user expresses doubt about the veracity of the vulnerability.
- Not patched: This vulnerability was not successfully patched by the user reporting the sighting.
Loading…
Loading…