VDB

DEBIAN-CVE-2024-52531

DEBIAN-CVE-2024-52531 PUBLISHED CVSS 6.5 MEDIUM

GNOME libsoup before 3.6.1 allows a buffer overflow in applications that perform conversion to UTF-8 in soup_header_parse_param_list_strict. There is a plausible way to reach this remotely via soup_message_headers_get_content_type (e.g., an application may want to retrieve the content type of a request or response).

Risk Scores

CVSS v3.1
6.5
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:L/I:L/A:L

Affected Products

VendorProductVersions
Debian:11libsoup2.40, 2.72.0-2, 2.72.0-2
Debian:14libsoup30, 0
Debian:13libsoup2.40, 0
Debian:12libsoup33.2.2-2, 0, 0
Debian:12libsoup2.40, 2.74.3-1, 0
Debian:13libsoup30, 0

Timeline

  • Nov 11, 2024 CVE Published
  • Apr 28, 2026 CVE Updated
Open in Interactive Console →
$ Console Community · 100/wk Open console ›