Back to Database
Status published
Medium
CVE-2011-2524
Directory traversal vulnerability in soup-uri.c in SoupServer in libsoup before...
Vulnerability Description
Directory traversal vulnerability in soup-uri.c in SoupServer in libsoup before 2.35.4 allows remote attackers to read arbitrary files via a %2e%2e (encoded dot dot) in a URI.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
THREAT MONITOR
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2011-2524
Credits & Attribution
No credits recorded in the NVD database.
References
- http://secunia.com/advisories/47299
- http://git.gnome.org/browse/libsoup/tree/NEWS
- http://lists.fedoraproject.org/pipermail/package-announce/2011-August/063431.html
- http://www.redhat.com/support/errata/RHSA-2011-1102.html
- http://www.securitytracker.com/id?1025864
- http://www.debian.org/security/2011/dsa-2369
- https://bugzilla.gnome.org/show_bug.cgi?id=653258
- http://www.ubuntu.com/usn/USN-1181-1
More from gnome
View All →CVE-2022-48622
In GNOME GdkPixbuf (aka gdk-pixbuf) through 2.42.10, the ANI (Windows...
Unknown
0
CVE-2022-37290
GNOME Nautilus 42.2 allows a NULL pointer dereference and get_basename...
Unknown
0
CVE-2022-29536
In GNOME Epiphany before 41.4 and 42.x before 42.2, an...
High
7.5
CVE-2022-27811
GNOME OCRFeeder before 0.8.4 allows OS command injection via shell...
Critical
9.8
CVE-2021-46829
GNOME GdkPixbuf (aka GDK-PixBuf) before 2.42.8 allows a heap-based buffer...
High
7.8
Affected Vendor
gnome
View all reports →Affected Software
libsoup
Vulnerable Versions:
0, 2.0, 2.2, 2.2.0, 2.2.1, 2.2.2, 2.2.3, 2.2.4, 2.2.5, 2.2.6, 2.2.6.1, 2.2.7, 2.2.91, 2.2.92, 2.2.93, 2.2.94, 2.2.95.1, 2.2.96, 2.2.97, 2.2.98, 2.2.99, 2.2.100, 2.2.101, 2.2.102, 2.2.103, 2.2.104, 2.3.0.1, 2.3.2, 2.3.4, 2.4.0, 2.4.1, 2.23.1, 2.23.6, 2.23.91, 2.23.92, 2.24.0.1, 2.24.1, 2.25.2, 2.25.3, 2.25.4, 2.25.5, 2.25.91, 2.26.0, 2.26.1, 2.27.1, 2.27.2, 2.27.4, 2.27.5, 2.27.90, 2.27.91, 2.27.92, 2.28.0, 2.28.1, 2.29.3, 2.29.5, 2.29.6, 2.29.90, 2.29.91, 2.30.0, 2.30.1, 2.31.2, 2.31.6, 2.31.90, 2.31.92, 2.32.0, 2.32.1, 2.32.2, 2.33.4, 2.33.5, 2.33.6, 2.33.90, 2.33.92, 2.34.0, 2.34.1
Timeline
Official Publish:
August 31st, 2011
Last Modified:
August 6th, 2024
Added to House:
July 19th, 2026
CVSS Vectors
Weaknesses (CWE)
No CWE data available
MITRE ATT&CK TTPs
No associated TTPs found for this vulnerability.