Name
CVE-2024-52531
Description
GNOME libsoup before 3.6.1 allows a buffer overflow in applications that perform conversion to UTF-8 in soup_header_parse_param_list_strict. There is a plausible way to reach this remotely via soup_message_headers_get_content_type (e.g., an application may want to retrieve the content type of a request or response).
CWEs
Published Date
Updated Date
Workaround
-
Advisories
https://gitlab.gnome.org/Teams/Releng/security/-/wikis/homeVendor Advisory
Analysis#
Vulnerability Ratings#
6.5
CVSSv31
8.4
CVSSv31
NaN
other
Others affected components#
Resolved with patches#
libsoup (buildroot:2025.02.x)
#
Title
Author
Resolve
1
headers: Be more robust against invalid input when
Changqing Li <changqing.li@windriver.com>
CVE-2024-52531
libsoup (buildroot:master)
#
Title
Author
Resolve
1
headers: Be more robust against invalid input when
Changqing Li <changqing.li@windriver.com>
CVE-2024-52531
libsoup (yocto:kirkstone)
#
Title
Author
Resolve
1
fuzzing: Cover soup_header_parse_param_list
Patrick Griffis <pgriffis@igalia.com>
CVE-2024-52531
2
headers: Be more robust against invalid input when parsing
Patrick Griffis <pgriffis@igalia.com>
CVE-2024-52531
3
tests: Add test for passing invalid UTF-8 to
Patrick Griffis <pgriffis@igalia.com>
CVE-2024-52531
libsoup-2.4 (yocto:kirkstone)
#
Title
Author
Resolve
1
headers: Be more robust against invalid input when
Patrick Griffis <pgriffis@igalia.com>
CVE-2024-52531
2
tests: Add test for passing invalid UTF-8 to
Patrick Griffis <pgriffis@igalia.com>
CVE-2024-52531
libsoup-2.4 (yocto:scarthgap)
#
Title
Author
Resolve
1
headers: Be more robust against invalid input when
Patrick Griffis <pgriffis@igalia.com>
CVE-2024-52531
2
tests: Add test for passing invalid UTF-8 to
Patrick Griffis <pgriffis@igalia.com>
CVE-2024-52531