CVE-2025-4035
Publication date 29 April 2025
Last updated 5 June 2025
Ubuntu priority
Cvss 3 Severity Score
A flaw was found in libsoup. When handling cookies, libsoup clients mistakenly allow cookies to be set for public suffix domains if the domain contains at least two components and includes an uppercase character. This bypasses public suffix protections and could allow a malicious website to set cookies for domains it does not own, potentially leading to integrity issues such as session fixation.
Status
Package | Ubuntu Release | Status |
---|---|---|
libsoup2.4 | 25.04 plucky |
Vulnerable, fix deferred
|
24.10 oracular |
Vulnerable, fix deferred
|
|
24.04 LTS noble |
Vulnerable, fix deferred
|
|
22.04 LTS jammy |
Vulnerable, fix deferred
|
|
20.04 LTS focal |
Vulnerable, fix deferred
|
|
18.04 LTS bionic |
Vulnerable, fix deferred
|
|
16.04 LTS xenial |
Vulnerable, fix deferred
|
|
libsoup3 | 25.04 plucky |
Vulnerable, fix deferred
|
24.10 oracular |
Vulnerable, fix deferred
|
|
24.04 LTS noble |
Vulnerable, fix deferred
|
|
22.04 LTS jammy |
Vulnerable, fix deferred
|
|
20.04 LTS focal | Not in release |
Notes
Patch details
Package | Patch details |
---|---|
libsoup3 |
Severity score breakdown
Parameter | Value |
---|---|
Base score |
|
Attack vector | Network |
Attack complexity | Low |
Privileges required | None |
User interaction | Required |
Scope | Unchanged |
Confidentiality | None |
Integrity impact | Low |
Availability impact | None |
Vector | CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N |