CVE-2024-52531
published 2024-11-11CVE-2024-52531: GNOME libsoup before 3.6.1 allows a buffer overflow in applications that perform conversion to UTF-8 in soup_header_parse_param_list_strict. There is a…
medium6.5CVSS 3.1
AVNACHPRNUINSCCLILAL
GNOME libsoup before 3.6.1 allows a buffer overflow in applications that perform conversion to UTF-8 in soup_header_parse_param_list_strict. There is a plausible way to reach this remotely via soup_message_headers_get_content_type (e.g., an application may want to retrieve the content type of a request or response).
Affected
7 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | libsoup2.4 | < libsoup2.4 2.74.3-1+deb12u1 (bookworm) | libsoup2.4 2.74.3-1+deb12u1 (bookworm) |
| debian | libsoup3 | < libsoup2.4 2.74.3-1+deb12u1 (bookworm) | libsoup2.4 2.74.3-1+deb12u1 (bookworm) |
| gnome | libsoup | < 3.6.1 | 3.6.1 |
| msrc | azl3_libsoup_3.4.4-2_on_azure_linux_3.0 | — | — |
| msrc | azl3_libsoup_3.4.4-6_on_azure_linux_3.0 | — | — |
| msrc | cbl2_libsoup_3.0.4-2_on_cbl_mariner_2.0 | — | — |
| msrc | cbl2_libsoup_3.0.4-4_on_cbl_mariner_2.0 | — | — |
CVSS provenance
nvdv3.16.5MEDIUMCVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:L/I:L/A:L
osv7.5HIGH