Your submission was sent successfully! Close

CVE-2017-2885

Published: 10 August 2017

An exploitable stack based buffer overflow vulnerability exists in the GNOME libsoup 2.58. A specially crafted HTTP request can cause a stack overflow resulting in remote code execution. An attacker can send a special HTTP request to the vulnerable server to trigger this vulnerability.

Priority

High

CVSS 3 base score: 9.8

Status

Package Release Status
libsoup2.4
Launchpad, Ubuntu, Debian
precise Does not exist

trusty Does not exist
(trusty was released [2.44.2-1ubuntu2.2])
upstream Needs triage

xenial
Released (2.52.2-1ubuntu0.2)
zesty
Released (2.56.0-2ubuntu0.1)
Patches:
upstream: https://git.gnome.org/browse/libsoup/commit/?id=03c91c76daf70ee227f38304c5e45a155f45073d