Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
Libsoup: libsoup: http request smuggling via unsigned to signed conversion error
Vulnerability Description
A flaw was found in libsoup. A remote attacker could exploit an unsigned to signed conversion error in the `soup_body_input_stream_read_chunked()` function by sending a malicious HTTP request. This vulnerability occurs when libsoup operates behind a non-libsoup proxy server or as a proxy in front of a non-libsoup backend server. Successful exploitation can allow an attacker to bypass security controls, poison web caches, or gain unauthorized access.
CVSS Information
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N
Vulnerability Type
HTTP请求的解释不一致性(HTTP请求私运)
Vulnerability Title
libsoup 安全漏洞
Vulnerability Description
libsoup是GNOME项目的一款GNOME的HTTP客户端/服务器库。 libsoup存在安全漏洞,该漏洞源于soup_body_input_stream_read_chunked函数中存在无符号到有符号转换错误,可能导致远程攻击者通过发送恶意HTTP请求绕过安全控制、污染Web缓存或获得未授权访问。
CVSS Information
N/A
Vulnerability Type
N/A