Integer Overflow in Cookie Parsing Logic of GNOME Applications
CVE-2025-4945
3.7LOW
What is CVE-2025-4945?
A flaw exists in the cookie parsing logic of the libsoup HTTP library, commonly used in GNOME applications, where improper validation of large integer inputs can lead to an integer overflow. This vulnerability allows an attacker to manipulate cookie expiration data, potentially bypassing the intended expiration logic. As a result, cookies may persist longer than expected or exhibit unintended behaviors, posing significant security risks in affected software environments.
References
CVSS V3.1
Score:
3.7
Severity:
LOW
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Red Hat would like to thank fouzhe for reporting this issue.