Integer Overflow in Cookie Parsing Logic of GNOME Applications
CVE-2025-4945

3.7LOW

What is CVE-2025-4945?

A flaw exists in the cookie parsing logic of the libsoup HTTP library, commonly used in GNOME applications, where improper validation of large integer inputs can lead to an integer overflow. This vulnerability allows an attacker to manipulate cookie expiration data, potentially bypassing the intended expiration logic. As a result, cookies may persist longer than expected or exhibit unintended behaviors, posing significant security risks in affected software environments.

References

CVSS V3.1

Score:
3.7
Severity:
LOW
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Red Hat would like to thank fouzhe for reporting this issue.
.