Your message dated Sat, 21 Dec 2024 17:17:09 +0000
with message-id <[email protected]>
and subject line Bug#1089240: fixed in libsoup2.4 2.74.3-1+deb12u1
has caused the Debian Bug report #1089240,
regarding libsoup2.4: CVE-2024-52531
to be marked as done.
This means that you claim that the problem has been dealt with.
If this is not the case it is now your responsibility to reopen the
Bug report if necessary, and/or fix the problem forthwith.
(NB: If you are a system administrator and have no idea what this
message is talking about, this may indicate a serious mail system
misconfiguration somewhere. Please contact [email protected]
immediately.)
--
1089240: https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1089240
Debian Bug Tracking System
Contact [email protected] with problems
--- Begin Message ---
Source: libsoup2.4
Version: 2.74.3-8
Severity: important
Tags: security upstream
X-Debbugs-Cc: [email protected], Debian Security Team <[email protected]>
Control: found -1 2.74.3-1
Hi,
The following vulnerability was published for libsoup2.4.
CVE-2024-52531[0]:
| GNOME libsoup before 3.6.1 allows a buffer overflow in applications
| that perform conversion to UTF-8 in
| soup_header_parse_param_list_strict. Input received over the network
| cannot trigger this.
If you fix the vulnerability please also make sure to include the
CVE (Common Vulnerabilities & Exposures) id in your changelog entry.
For further information see:
[0] https://security-tracker.debian.org/tracker/CVE-2024-52531
https://www.cve.org/CVERecord?id=CVE-2024-52531
Please adjust the affected versions in the BTS as needed.
-- System Information:
Debian Release: trixie/sid
APT prefers unstable
APT policy: (500, 'unstable'), (1, 'experimental')
Architecture: amd64 (x86_64)
Kernel: Linux 6.11.10-amd64 (SMP w/8 CPU threads; PREEMPT)
Locale: LANG=C.UTF-8, LC_CTYPE=C.UTF-8 (charmap=UTF-8), LANGUAGE not set
Shell: /bin/sh linked to /usr/bin/dash
Init: systemd (via /run/systemd/system)
LSM: AppArmor: enabled
--- End Message ---
--- Begin Message ---
Source: libsoup2.4
Source-Version: 2.74.3-1+deb12u1
Done: Sean Whitton <[email protected]>
We believe that the bug you reported is fixed in the latest version of
libsoup2.4, which is due to be installed in the Debian FTP archive.
A summary of the changes between this version and the previous one is
attached.
Thank you for reporting the bug, which will now be closed. If you
have further comments please address them to [email protected],
and the maintainer will reopen the bug report if appropriate.
Debian distribution maintenance software
pp.
Sean Whitton <[email protected]> (supplier of updated libsoup2.4 package)
(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing [email protected])
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA512
Format: 1.8
Date: Wed, 11 Dec 2024 10:52:05 +0800
Source: libsoup2.4
Architecture: source
Version: 2.74.3-1+deb12u1
Distribution: bookworm
Urgency: high
Maintainer: Debian GNOME Maintainers
<[email protected]>
Changed-By: Sean Whitton <[email protected]>
Closes: 1088812 1089238 1089240
Changes:
libsoup2.4 (2.74.3-1+deb12u1) bookworm; urgency=high
.
* Backport upstream fixes for
- CVE-2024-52530: HTTP request smuggling with null bytes at the end of
header names (Closes: #1088812)
- CVE-2024-52531: buffer overflow in soup_header_parse_param_list_strict
(Closes: #1089240)
- CVE-2024-52532: infinite loop / potential DoS in reading certain
data from WebSocket clients (Closes: #1089238).
Checksums-Sha1:
ad8a4e23ff73a84e5d6436bc65c8ce7e90711f90 3452 libsoup2.4_2.74.3-1+deb12u1.dsc
43e0dfcd57e8a52f69a01c6d38bfda0ab85a378c 30640
libsoup2.4_2.74.3-1+deb12u1.debian.tar.xz
Checksums-Sha256:
e093290083dfde935215b00758a5e92132118f93b92b513fe3152140675491cd 3452
libsoup2.4_2.74.3-1+deb12u1.dsc
c953dd7b7c4f208305909df0c48bfdb58a134d03a9ef20802981951c939b7b51 30640
libsoup2.4_2.74.3-1+deb12u1.debian.tar.xz
Files:
23b39a83c74e1a8c879353cc820bd766 3452 devel optional
libsoup2.4_2.74.3-1+deb12u1.dsc
0e89635a3bcd872e1d69ffecae9998f6 30640 devel optional
libsoup2.4_2.74.3-1+deb12u1.debian.tar.xz
-----BEGIN PGP SIGNATURE-----
iQIzBAEBCgAdFiEEm5FwB64DDjbk/CSLaVt65L8GYkAFAmdZYs8ACgkQaVt65L8G
YkD9sRAAvAX8LUtLW0PbxvL8XPQlO2Xtl/3lY66Nb5/9iyfwZ9Rl5dBP4evm2S9Q
Y019O7ihawCCEGm7SNZMg7fnbc9VauJ2EKMN7sAd25VTf5aQmE65i2YToiNiiJow
hX+3uR1GqPwmyZN3MIby0/CLTYa9MTC4h5KmmOi1k1ujkYQnXmzfvknMUuuKjv8j
02ZWHOs2QdkBOsn+TBW0BhkgMPHsKf+2IAPiRShHJIO5+om5N0+FT/CtXb+pUwj0
s9jPXUlfCOHrcWruOay69Y49PITlxr7EOcqGKj5B2Dq2a++SGOWinciDlz85Ui5o
iTTN18EaIHu84QjERsatH63/swo3IJTXA8yC0ii+9CyfzWQK/51K/myk09XoVry3
Vg6mtpqSz/c0zDiqHHa27ir4/MbHciiTlw6alGRED8k4jnbZz33LhojBR3W69ioj
AHlPHjaknLQ2PrDJkPCQk5MfNP28EOyc4HGdVUdiVwykCR30Hj9OZ1jA2F/zDbDA
LcL/3qQFxFIvB2d7qOekutQFq2rgZgin7xxaFzD/EdW1X3J5UZDS8pbhvNZwOlws
JxvFSR5Fi4Z5+RbbrHfvRo4E/jf0+cPCPMNdsBjG6oUGMMUdbGkgch2BHfYwZRoW
Zgg4X7RwoUgzt2GsBkqN2xPBSOv+czA/QZoPhKj85VovIMJogcs=
=NuFo
-----END PGP SIGNATURE-----
pgp7SvlQykuLz.pgp
Description: PGP signature
--- End Message ---