File _patchinfo of Package patchinfo.42105

<patchinfo incident="42105">
  <issue tracker="cve" id="2025-14523"/>
  <issue tracker="cve" id="2026-0719"/>
  <issue tracker="bnc" id="1254876">VUL-0: CVE-2025-14523: libsoup: Duplicate Host Header Handling Causes Host-Parsing Discrepancy (First- vs Last-Value Wins)</issue>
  <issue tracker="bnc" id="1256399">VUL-0: CVE-2026-0719: libsoup,libsoup2: stack-based buffer overflow in NTLM authentication can lead to arbitrary code execution</issue>
  <packager>AZhou</packager>
  <rating>important</rating>
  <category>security</category>
  <summary>Security update for libsoup</summary>
  <description>This update for libsoup fixes the following issues:

- CVE-2025-14523: Reject duplicated Host in headers and followed 
  upsteram update (bsc#1254876).
- CVE-2026-0719: Fixed overflow for password md4sum (bsc#1256399)
</description>
</patchinfo>
openSUSE Build Service is sponsored by