#VU109927 Buffer Over-read in libsoup - CVE-2025-32053
Published: May 29, 2025
libsoup
Gnome Development Team
Description
The vulnerability allows a remote attacker to gain access to sensitive information.
The vulnerability exists due to a boundary error within the sniff_feed_or_html() and skip_insignificant_space() functions when parsing server HTTP response. A remote attacker can trick the victim into visiting a specially crafted website and read parts of the heap memory.