Your message dated Wed, 9 Apr 2025 09:51:58 +0200
with message-id <[email protected]>
and subject line Re: libsoup2.4: CVE-2025-32051
has caused the Debian Bug report #1102213,
regarding libsoup2.4: CVE-2025-32051
to be marked as done.
This means that you claim that the problem has been dealt with.
If this is not the case it is now your responsibility to reopen the
Bug report if necessary, and/or fix the problem forthwith.
(NB: If you are a system administrator and have no idea what this
message is talking about, this may indicate a serious mail system
misconfiguration somewhere. Please contact [email protected]
immediately.)
--
1102213: https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1102213
Debian Bug Tracking System
Contact [email protected] with problems
--- Begin Message ---
Source: libsoup2.4
Version: 2.74.3-9
Severity: important
Tags: security upstream
Forwarded: https://gitlab.gnome.org/GNOME/libsoup/-/issues/401
X-Debbugs-Cc: [email protected], Debian Security Team <[email protected]>
Hi,
The following vulnerability was published for libsoup2.4.
CVE-2025-32051[0]:
| A flaw was found in libsoup. The libsoup soup_uri_decode_data_uri()
| function may crash when processing malformed data URI. This flaw
| allows an attacker to cause a denial of service (DoS).
The code was refactored in 2.99.1 with 737eef099ca1 ("Replace SoupURI
with GUri") upstream but the same underlying code seems present in the
original implementation, but I'm not 100% certain. Please
double-check.
If you fix the vulnerability please also make sure to include the
CVE (Common Vulnerabilities & Exposures) id in your changelog entry.
For further information see:
[0] https://security-tracker.debian.org/tracker/CVE-2025-32051
https://www.cve.org/CVERecord?id=CVE-2025-32051
[1] https://gitlab.gnome.org/GNOME/libsoup/-/issues/401
Please adjust the affected versions in the BTS as needed.
Regards,
Salvatore
--- End Message ---
--- Begin Message ---
Hi Sylvain,
On Tue, Apr 08, 2025 at 11:10:12PM +0200, Sylvain Beucler wrote:
> Hi,
>
> On Sun, 06 Apr 2025 14:25:36 +0200 Salvatore Bonaccorso <[email protected]>
> wrote:
> > The code was refactored in 2.99.1 with 737eef099ca1 ("Replace SoupURI
> > with GUri") upstream but the same underlying code seems present in the
> > original implementation, but I'm not 100% certain. Please
> > double-check.
> AFAICS the code was introduced (in SoupURI form) along with the
> 'soup_uri_decode_data_uri' function a bit before that in
> https://gitlab.gnome.org/GNOME/libsoup/-/commit/9f42c7b8dc1d099b1464070ca993189bf7a3cdd0
> (still in 2.99.1).
>
> I believe libsoup2.4 is <not-affected>.
Thanks, I think to agree and have updated now the security-tracker.
Regards,
Salvatore
--- End Message ---