Advisories ยป MGASA-2024-0382

Updated libsoup3 & libsoup packages fix security vulnerabilities

Publication date: 29 Nov 2024
Modification date: 29 Nov 2024
Type: security
Affected Mageia releases : 9
CVE: CVE-2024-52530 , CVE-2024-52531 , CVE-2024-52532

Description

GNOME libsoup before 3.6.0 allows HTTP request smuggling in some
configurations because '\0' characters at the end of header names are
ignored, i.e., a "Transfer-Encoding\0: chunked" header is treated the
same as a "Transfer-Encoding: chunked" header. (CVE-2024-52530)
GNOME libsoup before 3.6.1 allows a buffer overflow in applications that
perform conversion to UTF-8 in soup_header_parse_param_list_strict.
Input received over the network cannot trigger this. (CVE-2024-52531)
GNOME libsoup before 3.6.1 has an infinite loop, and memory consumption.
during the reading of certain patterns of WebSocket data from clients.
(CVE-2024-52532)
                

References

SRPMS

9/core