CVE-2018-12910
published 2018-07-05CVE-2018-12910: The get_cookies function in soup-cookie-jar.c in libsoup 2.63.2 allows attackers to have unspecified impact via an empty hostname.
PriorityP340critical9.8CVSS 3.0
AVNACLPRNUINSUCHIHAH
EPSS
4.19%
89.8th percentile
The get_cookies function in soup-cookie-jar.c in libsoup 2.63.2 allows attackers to have unspecified impact via an empty hostname.
Affected
14 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| debian | libsoup2.4 | < libsoup2.4 2.62.2-2 (bookworm) | libsoup2.4 2.62.2-2 (bookworm) |
| gnome | libsoup | — | — |
| opensuse | leap | — | — |
| redhat | ansible_tower | — | — |
| redhat | enterprise_linux_desktop | — | — |
| redhat | enterprise_linux_server | — | — |
| redhat | enterprise_linux_workstation | — | — |
| redhat | openshift_container_platform | — | — |
CVSS provenance
nvdv3.09.8CRITICALCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
osv9.8CRITICAL
vendor_debian9.8CRITICAL
vendor_redhat9.8CRITICAL
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-wv8f-jq6c-45j5: The get_cookies function in soup-cookie-jar
ghsa_unreviewed·2022-05-14
CVE-2018-12910 [CRITICAL] CWE-125 GHSA-wv8f-jq6c-45j5: The get_cookies function in soup-cookie-jar
The get_cookies function in soup-cookie-jar.c in libsoup 2.63.2 allows attackers to have unspecified impact via an empty hostname.
OSV
CVE-2018-12910: The get_cookies function in soup-cookie-jar
osv·2018-07-05·CVSS 9.8
CVE-2018-12910 [CRITICAL] CVE-2018-12910: The get_cookies function in soup-cookie-jar
The get_cookies function in soup-cookie-jar.c in libsoup 2.63.2 allows attackers to have unspecified impact via an empty hostname.
Red Hat
libsoup: Crash in soup_cookie_jar.c:get_cookies() on empty hostnames
vendor_redhat·2018-07-03·CVSS 9.8
CVE-2018-12910 [CRITICAL] CWE-125 libsoup: Crash in soup_cookie_jar.c:get_cookies() on empty hostnames
libsoup: Crash in soup_cookie_jar.c:get_cookies() on empty hostnames
The get_cookies function in soup-cookie-jar.c in libsoup 2.63.2 allows attackers to have unspecified impact via an empty hostname.
An out-of-bounds read has been discovered in libsoup when getting cookies from a URI with empty hostname. An attacker may use this flaw to cause a crash in the application.
Package: libsoup (Red Hat Enterprise Linux 6) - Will not fix
Package: libsoup (Red Hat Enterprise Linux 8) - Not affected
Ubuntu
libsoup vulnerability
vendor_ubuntu·2018-07-03
CVE-2018-12910 libsoup vulnerability
Title: libsoup vulnerability
Summary: libsoup could be made to crash if it received a specially crafted
input.
It was discovered that libsoup incorrectly handled certain cookie requests.
An attacker could possibly use this to cause a denial of service.
Instructions: In general, a standard system update will make all the necessary changes.
Debian
CVE-2018-12910: libsoup2.4 - The get_cookies function in soup-cookie-jar.c in libsoup 2.63.2 allows attackers...
vendor_debian·2018·CVSS 9.8
CVE-2018-12910 [CRITICAL] CVE-2018-12910: libsoup2.4 - The get_cookies function in soup-cookie-jar.c in libsoup 2.63.2 allows attackers...
The get_cookies function in soup-cookie-jar.c in libsoup 2.63.2 allows attackers to have unspecified impact via an empty hostname.
Scope: local
bookworm: resolved (fixed in 2.62.2-2)
bullseye: resolved (fixed in 2.62.2-2)
trixie: resolved (fixed in 2.62.2-2)
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2018-12910 mingw-libsoup: libsoup: Crash in soup_cookie_jar.c:get_cookies() on empty hostnames [fedora-all]
bugzilla·2018-07-04·CVSS 9.8
CVE-2018-12910 [CRITICAL] CVE-2018-12910 mingw-libsoup: libsoup: Crash in soup_cookie_jar.c:get_cookies() on empty hostnames [fedora-all]
CVE-2018-12910 mingw-libsoup: libsoup: Crash in soup_cookie_jar.c:get_cookies() on empty hostnames [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue a
Bugzilla
CVE-2018-12910 libsoup: Crash in soup_cookie_jar.c:get_cookies() on empty hostnames
bugzilla·2018-07-04·CVSS 9.8
CVE-2018-12910 [CRITICAL] CVE-2018-12910 libsoup: Crash in soup_cookie_jar.c:get_cookies() on empty hostnames
CVE-2018-12910 libsoup: Crash in soup_cookie_jar.c:get_cookies() on empty hostnames
libsoup through version 2.63.2 is vulnerable to a crash in the soup_cookie_jar.c:get_cookies() when handling empty hostnames.
Upstream Patch:
https://gitlab.gnome.org/GNOME/libsoup/commit/db2b0d5809d5f8226d47312b40992cadbcde439f
Discussion:
Created libsoup tracking bugs for this issue:
Affects: fedora-all [bug 1597982]
Created mingw-libsoup tracking bugs for this issue:
Affects: fedora-all [bug 1597981]
---
Reference:
https://usn.ubuntu.com/3701-1/
---
Reproduced on f27 with libsoup-2.60.3-1.fc27.x86_64:
sh-4.4# gcc -fsanitize=address -g cookies-test.c test-utils.c -I/usr/include/libsoup-2.4/ -I/usr/include/glib-2.0/ -I/usr/lib64/glib-2.0/include/ -lsoup-2.4 -lgio-2.0 -lgobject-2.0 -lglib-2.
Bugzilla
CVE-2018-12910 libsoup: Crash in soup_cookie_jar.c:get_cookies() on empty hostnames [fedora-all]
bugzilla·2018-07-04·CVSS 9.8
CVE-2018-12910 [CRITICAL] CVE-2018-12910 libsoup: Crash in soup_cookie_jar.c:get_cookies() on empty hostnames [fedora-all]
CVE-2018-12910 libsoup: Crash in soup_cookie_jar.c:get_cookies() on empty hostnames [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple
http://lists.opensuse.org/opensuse-security-announce/2019-05/msg00003.htmlhttps://access.redhat.com/errata/RHBA-2019:0327https://access.redhat.com/errata/RHSA-2018:3140https://access.redhat.com/errata/RHSA-2018:3505https://gitlab.gnome.org/GNOME/gnome-sdk-images/commit/4215b8a21b3b3055e947312a8920df94f93ba047https://gitlab.gnome.org/GNOME/libsoup/commit/db2b0d5809d5f8226d47312b40992cadbcde439fhttps://gitlab.gnome.org/GNOME/libsoup/issues/3https://lists.debian.org/debian-lts-announce/2018/07/msg00007.htmlhttps://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/SBREWZ3EEDYWG6PCLWL2EJ24ME5ZFAX6/https://usn.ubuntu.com/3701-1/https://www.debian.org/security/2018/dsa-4241http://lists.opensuse.org/opensuse-security-announce/2019-05/msg00003.htmlhttps://access.redhat.com/errata/RHBA-2019:0327https://access.redhat.com/errata/RHSA-2018:3140https://access.redhat.com/errata/RHSA-2018:3505https://gitlab.gnome.org/GNOME/gnome-sdk-images/commit/4215b8a21b3b3055e947312a8920df94f93ba047https://gitlab.gnome.org/GNOME/libsoup/commit/db2b0d5809d5f8226d47312b40992cadbcde439fhttps://gitlab.gnome.org/GNOME/libsoup/issues/3https://lists.debian.org/debian-lts-announce/2018/07/msg00007.htmlhttps://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/SBREWZ3EEDYWG6PCLWL2EJ24ME5ZFAX6/https://usn.ubuntu.com/3701-1/https://www.debian.org/security/2018/dsa-4241
2018-07-05
Published