cbcvebase.
CVE-2024-52531
published 2024-11-11

CVE-2024-52531: GNOME libsoup before 3.6.1 allows a buffer overflow in applications that perform conversion to UTF-8 in soup_header_parse_param_list_strict. There is a…

medium6.5CVSS 3.1
AVNACHPRNUINSCCLILAL
GNOME libsoup before 3.6.1 allows a buffer overflow in applications that perform conversion to UTF-8 in soup_header_parse_param_list_strict. There is a plausible way to reach this remotely via soup_message_headers_get_content_type (e.g., an application may want to retrieve the content type of a request or response).

Affected

7 ranges
VendorProductVersion rangeFixed in
debianlibsoup2.4< libsoup2.4 2.74.3-1+deb12u1 (bookworm)libsoup2.4 2.74.3-1+deb12u1 (bookworm)
debianlibsoup3< libsoup2.4 2.74.3-1+deb12u1 (bookworm)libsoup2.4 2.74.3-1+deb12u1 (bookworm)
gnomelibsoup< 3.6.13.6.1
msrcazl3_libsoup_3.4.4-2_on_azure_linux_3.0
msrcazl3_libsoup_3.4.4-6_on_azure_linux_3.0
msrccbl2_libsoup_3.0.4-2_on_cbl_mariner_2.0
msrccbl2_libsoup_3.0.4-4_on_cbl_mariner_2.0

CVSS provenance

nvdv3.16.5MEDIUMCVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:L/I:L/A:L
osv7.5HIGH