f17a577dc6
Add libsoup-CVE-2025-12105.patch
Mike Gorse2025-12-15 20:02:26 -05:00
388bb6b2eb
Accepting request 1319178 from GNOME:Factory
Ana Guerrero2025-11-25 14:50:58 +00:00
e4b62c2e4a
- Add libsoup-CVE-2025-12105.patch: fix use after free caused by 'finishing' queue item twice (bsc#1252555 CVE-2025-12105 glgo#GNOME/libsoup!481). - Add i586 to the list of architectures where we re-run tests; hsts-db-test is timing out there as well.
Bjørn Lie2025-11-21 20:17:06 +00:00
6ec247ad06
- Add libsoup-CVE-2025-4969.patch: multipart: verify array bounds before accesing its members (boo#1243423 CVE-2025-4969). - Also rerun tests for ppc64le should they fail. hsts-db-test appears to time out intermittently there (bsc#1243570).
Bjørn Lie2025-05-29 04:59:02 +00:00
d2d47dac33
- Add libsoup-CVE-2025-4476.patch: fix crash in soup_auth_digest_get_protection_space (boo#1243422 CVE-2025-4476 glgo#GNOME/libsoup!457). - Add libsoup-CVE-2025-4948.patch: verify boundary limits for multipart body (boo#1243332 CVE-2025-4948 glgo#GNOME/libsoup#449).
Bjørn Lie2025-05-28 05:55:20 +00:00
f49ae351ef
Accepting request 1278245 from GNOME:Factory
Ana Guerrero2025-05-20 07:35:27 +00:00
3c5ff2379b
Accepting request 1228510 from GNOME:Factory
Ana Guerrero2024-12-06 13:25:12 +00:00
0ef907eabc
- Increase test timeout on s390x. The http2-body-stream test can be slow and sometimes times out in our builds.
Bjørn Lie2024-12-05 12:42:12 +00:00
49d29e3b08
Accepting request 1226285 from GNOME:Factory
Ana Guerrero2024-11-26 19:54:51 +00:00
3b6b89924d
- Update to version 3.6.1: + Fix soup_uri_copy() reading port as a long instead of an int + Fix possible NULL deref in soup_uri_decode_data_uri() + Fix possible overflow in SoupContentSniffer + Fix assertion in soup_uri_decode_data_uri() on URLs with a path starting with // + headers: Be more robust against invalid input when parsing params + websocket: Fix possibility of being stuck in a read loop - Drop patches fixed upstream: + 6adc0e3e.patch + 29b96fab.patch + a35222dd.patch + 4c9e75c6.patch
Dominique Leuenberger2024-11-25 14:18:24 +00:00
6b01ab76cf
Accepting request 1224047 from GNOME:Factory
Ana Guerrero2024-11-15 14:37:51 +00:00
baea141022
Accepting request 1224037 from GNOME:Next
Bjørn Lie2024-11-13 22:53:52 +00:00
79f891224f
Accepting request 1223846 from GNOME:Factory
Ana Guerrero2024-11-13 14:27:22 +00:00
7ab00daf42
- Add 6adc0e3e.patch: websocket: Process the frame as soon as we read data (boo#1233287 CVE-2024-52532 glgo#GNOME/libsoup#391). - Add 29b96fab.patch: websocket-test: disconnect error copy after the test ends (glgo#GNOME/libsoup#391). - Add a35222dd.patch: be more robust against invalid input when parsing params (boo#1233292 CVE-2024-52531 glgo#GNOME/libsoup!407).
Bjørn Lie2024-11-13 07:23:46 +00:00
2502aa2d33
Accepting request 1196080 from GNOME:Factory
Ana Guerrero2024-08-27 17:38:29 +00:00
88869ea8ee
- Update to version 3.6.0: + Allow HTTP/2 to be used with non-HTTP proxies - Changes from version 3.5.2: + Strictly forbid NUL bytes in headers + Fix minor leaks - Changes from version 3.5.1: + Add SOUP_METHOD_PATCH + websocket: Add SoupWebsocketConnection:keepalive-pong-timeout property + Increase maxmimum size of HTTP headers + Fix soup_uri_copy() in Vala + Fix leak in soup_message_new_from_encoded_form() + multipart: Improve handling of messages missing termination + logger: - Fix request filter function being called with response user data - Fix response bodies never being logged if request bodies aren't - Add Soup-Host to logged headers for when Host is missing + cookies: - Fix incorrect logic in determining same-site cookies - Limit the Max-Age to 1 year + cookie-jar-db: Explicitly handle old databases lacking same-site column
Bjørn Lie2024-08-26 13:43:05 +00:00
5f56db386b
Accepting request 1120815 from GNOME:Factory
Ana Guerrero2023-10-29 18:39:40 +00:00
444cc38429
Accepting request 1120638 from GNOME:Next
Bjørn Lie2023-10-27 13:50:06 +00:00
501ab7f9a5
- BuildIgnore polkit: sysprof pulls in polkit-devel/polkit, which is correct, but for our build not needed. This helps us break up a build cycle.
Dominique Leuenberger2020-11-12 14:18:10 +00:00