VUL-0: CVE-2024-52530: libsoup,libsoup2: HTTP request smuggling via stripping null bytes from the ends of header names
VUL-0: CVE-2024-52532: libsoup,libsoup2: libsoup: infinite loop while reading websocket data
VUL-0: CVE-2024-52531: libsoup,libsoup2: libsoup: buffer overflow via UTF-8 conversion in soup_header_parse_param_list_strict
mgorse
important
security
Security update for libsoup2
This update for libsoup2 fixes the following issues:
- CVE-2024-52530: HTTP request smuggling via stripping null bytes from the ends of header names (bsc#1233285).
- CVE-2024-52532: infinite loop while reading websocket data (bsc#1233287).
- CVE-2024-52531: buffer overflow via UTF-8 conversion in soup_header_parse_param_list_strict (bsc#1233292).
libsoup2