Your message dated Tue, 10 Dec 2024 05:49:00 +0000
with message-id <[email protected]>
and subject line Bug#1089238: fixed in libsoup2.4 2.74.3-8.1
has caused the Debian Bug report #1089238,
regarding libsoup2.4: CVE-2024-52532
to be marked as done.

This means that you claim that the problem has been dealt with.
If this is not the case it is now your responsibility to reopen the
Bug report if necessary, and/or fix the problem forthwith.

(NB: If you are a system administrator and have no idea what this
message is talking about, this may indicate a serious mail system
misconfiguration somewhere. Please contact [email protected]
immediately.)


-- 
1089238: https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1089238
Debian Bug Tracking System
Contact [email protected] with problems
--- Begin Message ---
Source: libsoup2.4
Version: 2.74.3-8
Severity: important
Tags: security upstream
Forwarded: https://gitlab.gnome.org/GNOME/libsoup/-/issues/391
X-Debbugs-Cc: [email protected], Debian Security Team <[email protected]>
Control: found -1 2.74.3-1

Hi,

The following vulnerability was published for libsoup2.4.

CVE-2024-52532[0]:
| GNOME libsoup before 3.6.1 has an infinite loop, and memory
| consumption. during the reading of certain patterns of WebSocket
| data from clients.


If you fix the vulnerability please also make sure to include the
CVE (Common Vulnerabilities & Exposures) id in your changelog entry.

For further information see:

[0] https://security-tracker.debian.org/tracker/CVE-2024-52532
    https://www.cve.org/CVERecord?id=CVE-2024-52532
[1] https://gitlab.gnome.org/GNOME/libsoup/-/issues/391
[2] https://gitlab.gnome.org/GNOME/libsoup/-/merge_requests/410

Please adjust the affected versions in the BTS as needed.

Regards,
Salvatore

--- End Message ---
--- Begin Message ---
Source: libsoup2.4
Source-Version: 2.74.3-8.1
Done: Sean Whitton <[email protected]>

We believe that the bug you reported is fixed in the latest version of
libsoup2.4, which is due to be installed in the Debian FTP archive.

A summary of the changes between this version and the previous one is
attached.

Thank you for reporting the bug, which will now be closed.  If you
have further comments please address them to [email protected],
and the maintainer will reopen the bug report if appropriate.

Debian distribution maintenance software
pp.
Sean Whitton <[email protected]> (supplier of updated libsoup2.4 package)

(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing [email protected])


-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA512

Format: 1.8
Date: Tue, 10 Dec 2024 13:17:25 +0800
Source: libsoup2.4
Architecture: source
Version: 2.74.3-8.1
Distribution: unstable
Urgency: high
Maintainer: Debian GNOME Maintainers 
<[email protected]>
Changed-By: Sean Whitton <[email protected]>
Closes: 1088812 1089238 1089240
Changes:
 libsoup2.4 (2.74.3-8.1) unstable; urgency=high
 .
   * Non-maintainer upload.
   * Backport upstream fixes for
     - CVE-2024-52530: HTTP request smuggling with null bytes at the end of
       header names (Closes: #1088812)
     - CVE-2024-52531: buffer overflow in soup_header_parse_param_list_strict
       (Closes: #1089240)
     - CVE-2024-52532: infinite loop / potential DoS in reading certain
       data from WebSocket clients (Closes: #1089238).
Checksums-Sha1:
 b294f867224cb49bd18b82cd00b49a5d945acb40 3497 libsoup2.4_2.74.3-8.1.dsc
 cc123495342082013ac74d08da6472f6adfa8025 31156 
libsoup2.4_2.74.3-8.1.debian.tar.xz
Checksums-Sha256:
 e67ed6389d45bddee817d3dcfa3ae595471c1de9cd335ea9226345af766e6ff4 3497 
libsoup2.4_2.74.3-8.1.dsc
 55ad94945e031d010d42ee51fda23d7506cc88517f5db276e9f58866720b450c 31156 
libsoup2.4_2.74.3-8.1.debian.tar.xz
Files:
 410a9719c109cba4525d645b9d0de0a8 3497 oldlibs optional 
libsoup2.4_2.74.3-8.1.dsc
 ddbfc61735c771cb2534de6016fad99e 31156 oldlibs optional 
libsoup2.4_2.74.3-8.1.debian.tar.xz

-----BEGIN PGP SIGNATURE-----

iQIzBAEBCgAdFiEEm5FwB64DDjbk/CSLaVt65L8GYkAFAmdX0rsACgkQaVt65L8G
YkBniw/9ERwuk0hVsWXh3E3NduK/kKosYOP7I97DjkvJ0nAFfiiO0EKgX98udSuv
E9l/jF67LEkvK5qzOVw5XLnxYG/f/JKJULTHxAZviGkqvve2uxp4GXLOTvAtom60
Ht1jcCFL+Cac3VzW5Bib/w8pJtck4JSzuYa8YYnIPJ06fD/lA7Y2PAyyL3nNeyP3
7UTNTF9cBHkNgO2peACA/nSuwHbWGFj+lpCz8WCiTCHrRBzo6PC9b8pamCjgwuMC
l2HtaDvEImdUngPgyz0/gfZSNOD/7HoA4pOpvuuCaBKCKPKJbEVCwVVDxp3o6NWV
W8+Tbg90F4K4V6s/GO6gb3/wqYin2gN6dfDep4MSo9A7NSYu5RqE7emIpCvkJnWZ
24E68ximzCUYcktH/2An1w/noMTDnGyBEQWewLZ3aTV3x9jE8oS6Qdx5e38wFcjq
Fu8GZvI/hCG6Rf76z3CE9hZmI/ETdf2vCpq2pq/JkAum8WTh2EqPAymCEYmL8xdK
NH2o4H5AV4snav4mhKISySL8GhZTmHIyaExhWx3zG5TRyhJn/4JKxOim2ebVqcJX
spAqDhCzl2Vpxy/+6GZYRROrZUFuoOpRLV7fXBIILs6vy41DQTeayuXuDTyBD7G+
J4fK4Q5OJg2c1rLUJ8kUKaI2pdJ2mAUREDfYGVPYKgDwFALWCGw=
=2Jb5
-----END PGP SIGNATURE-----

Attachment: pgpwcTk_2ylSD.pgp
Description: PGP signature


--- End Message ---

Reply via email to