New Debian libsoup2.4 2.74.3-1+deb12u1 fixes: This update addresses the following issues: * libsoup: HTTP request smuggling via stripping null bytes from the ends of header names (CVE-2024-52530) * libsoup: buffer overflow via UTF-8 conversion in soup_header_parse_param_list_strict (CVE-2024-52531) * libsoup: infinite loop while reading websocket data (CVE-2024-52532)
--- mirror/ftp/pool/main/libs/libsoup2.4/libsoup2.4_2.74.3-1.dsc +++ apt/ucs_5.2-0-errata5.2-0/source/libsoup2.4_2.74.3-1+deb12u1.dsc @@ -1,3 +1,13 @@ +2.74.3-1+deb12u1 [Wed, 11 Dec 2024 10:52:05 +0800] Sean Whitton <spwhitton@spwhitton.name>: + + * Backport upstream fixes for + - CVE-2024-52530: HTTP request smuggling with null bytes at the end of + header names (Closes: #1088812) + - CVE-2024-52531: buffer overflow in soup_header_parse_param_list_strict + (Closes: #1089240) + - CVE-2024-52532: infinite loop / potential DoS in reading certain + data from WebSocket clients (Closes: #1089238). + 2.74.3-1 [Tue, 11 Oct 2022 15:28:32 -0400] Jeremy Bicha <jbicha@ubuntu.com>: * New upstream release (LP: #1992504) <http://piuparts.knut.univention.de/5.2-0/#7453794063408561969>
OK: bug OK: yaml OK: announce_errata OK: patch OK: piuparts [5.2-0] 3037cc147d Bug #57924: libsoup2.4 2.74.3-1+deb12u1 doc/errata/staging/libsoup2.4.yaml | 19 +++++++++++++++++++ 1 file changed, 19 insertions(+)
<https://errata.software-univention.de/#/?erratum=5.2x9>