CVE-2018-12910
Summary
| CVE | CVE-2018-12910 |
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2018-07-05 18:29:00 UTC |
| Updated | 2023-11-07 02:52:00 UTC |
| Description | The get_cookies function in soup-cookie-jar.c in libsoup 2.63.2 allows attackers to have unspecified impact via an empty hostname. |
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|
| Red Hat Customer Portal |
REDHAT |
access.redhat.com |
Third Party Advisory |
| Red Hat Customer Portal |
REDHAT |
access.redhat.com |
Third Party Advisory |
| cookie-jar: bail if hostname is an empty string (db2b0d58) · Commits · GNOME / libsoup · GitLab |
CONFIRM |
gitlab.gnome.org |
Patch, Third Party Advisory, Vendor Advisory |
| [SECURITY] Fedora 28 Update: libsoup-2.62.2-2.fc28 - package-announce - Fedora Mailing-Lists |
FEDORA |
lists.fedoraproject.org |
Release Notes, Third Party Advisory, Vendor Advisory |
| [security-announce] openSUSE-SU-2019:1310-1: moderate: Security update f |
SUSE |
lists.opensuse.org |
Mailing List, Third Party Advisory |
| [SECURITY] [DLA 1416-1] libsoup2.4 security update |
MLIST |
lists.debian.org |
Mailing List, Third Party Advisory |
| (CVE-2018-12910) soup-cookie-jar.c out of bound read (#3) · Issues · GNOME / libsoup · GitLab |
CONFIRM |
gitlab.gnome.org |
Third Party Advisory |
| libsoup: Fix CVE-2018-12910 (4215b8a2) · Commits · Archive / gnome-sdk-images · GitLab |
CONFIRM |
gitlab.gnome.org |
Patch, Third Party Advisory |
| Debian -- Security Information -- DSA-4241-1 libsoup2.4 |
DEBIAN |
www.debian.org |
Third Party Advisory |
| USN-3701-1: libsoup vulnerability | Ubuntu security notices | Ubuntu |
UBUNTU |
usn.ubuntu.com |
Third Party Advisory |
| [SECURITY] Fedora 28 Update: libsoup-2.62.2-2.fc28 - package-announce - Fedora Mailing-Lists |
|
lists.fedoraproject.org |
|
| Red Hat Customer Portal |
REDHAT |
access.redhat.com |
Third Party Advisory |
| CVE Program record |
CVE.ORG |
www.cve.org |
canonical |
| NVD vulnerability detail |
NVD |
nvd.nist.gov |
canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 296079 Oracle Solaris 11.4 Support Repository Update (SRU) 15.5.0 Missing (CPUOCT2019)