CVE-2024-52531: Buffer Overflow
GNOME libsoup before 3.6.1 allows a buffer overflow in applications that perform conversion to UTF-8 in soupheaderparseparamliststrict.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
debian/libsoup3to a version that resolves this vulnerability.Fixed in 3.6.1-1 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 3.0.4-2 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 3.4.4-2 - Upgrade
Upgrade
GNOME libsoupto a version that resolves this vulnerability.Fixed in 3.6.1 - Compensating control
Because the issue is described as plausibly reachable remotely via soup_message_headers_get_content_type (e.g., applications retrieving request/response Content-Type), restrict network access to the affected application(s) and their request-handling endpoints to trusted clients to reduce the chance of triggering the remote attack path.
Event History
Frequently Asked Questions
What is the severity of CVE-2024-52531?
CVE-2024-52531 is classified as a high severity vulnerability due to its potential for causing buffer overflow issues.
How do I fix CVE-2024-52531?
To fix CVE-2024-52531, upgrade to libsoup3 version 3.6.1-1 or later.
Which versions of libsoup are affected by CVE-2024-52531?
CVE-2024-52531 affects libsoup versions before 3.6.1 and certain earlier versions of libsoup2.4.
Can CVE-2024-52531 be exploited remotely?
No, CVE-2024-52531 cannot be triggered by input received over the network.
What should I do if I cannot upgrade to the patched version for CVE-2024-52531?
If you cannot upgrade, consider applying security measures such as input validation to mitigate risks associated with CVE-2024-52531.