USN-7126-1: libsoup vulnerabilities
It was discovered that libsoup ignored certain characters at the end of header names. A remote attacker could possibly use this issue to perform a HTTP request smuggling attack. (CVE-2024-52530) It was discovered that libsoup did not correctly handle memory while performing UTF-8 conversions. An attacker could possibly use this issue to cause a denial of service or execute arbitrary code. (CVE-2024-52531) It was discovered that libsoup could enter an infinite loop when reading certain websocket data. An attacker could possibly use this issue to cause a denial of service. (CVE-2024-52532)
Affected Software
Event History
Child vulnerabilities
Contains the following vulnerabilities.
Frequently Asked Questions
What is the severity of USN-7126-1?
The severity of USN-7126-1 is considered high due to the potential for HTTP request smuggling attacks.
How do I fix USN-7126-1?
To fix USN-7126-1, upgrade the libsoup package to the latest version specified for your Ubuntu release.
What systems are affected by USN-7126-1?
USN-7126-1 affects multiple Ubuntu versions including 18.04, 20.04, 22.04, 24.04, and 24.10.
Is it safe to use applications relying on libsoup-2.4-1 after USN-7126-1?
Using applications relying on libsoup-2.4-1 without applying the patch from USN-7126-1 poses security risks due to the vulnerability.
What is CVE-2024-52530 in relation to USN-7126-1?
CVE-2024-52530 is the identifier for the specific vulnerability addressed in USN-7126-1 regarding the improper handling of header names in libsoup.