Alerts This Week
Warning Icon 1 727
Alerts This Week
Warning Icon 1 727

Fedora 41: libsoup3 Update for CVE-2024-52531 moderate: buffer overflow

fedora
Calendar Grey January 29, 2025
Dist Fedora Esm H88
The latest Fedora 41 release for libsoup3 resolves a critical buffer overflow vulnerability, improving overall system security.
Fix for CVE-2024-52531

Summary

Libsoup is an HTTP library implementation in C. It was originally part

of a SOAP (Simple Object Access Protocol) implementation called Soup, but

the SOAP and non-SOAP parts have now been split into separate packages.

libsoup uses the Glib main loop and is designed to work well with GTK

applications. This enables GNOME applications to access HTTP servers

on the network in a completely asynchronous fashion, very similar to

the Gtk+ programming model (a synchronous operation mode is also

supported for those who want it), but the SOAP parts were removed

long ago.

Update Information:

Fix for CVE-2024-52531

Change Log

* Mon Jan 20 2025 nmontero - 3.6.4-1 - Update to 3.6.4 * Mon Jan 20 2025 Fedora Release Engineering - 3.6.3-3 - Rebuilt for https://fedoraproject.org/wiki/Fedora_42_Mass_Rebuild * Fri Jan 17 2025 Fedora Release Engineering - 3.6.3-2 - Rebuilt for https://fedoraproject.org/wiki/Fedora_42_Mass_Rebuild * Mon Jan 13 2025 nmontero - 3.6.3-1 - Update to 3.6.3 * Mon Nov 25 2024 nmontero - 3.6.1-1 - Update to 3.6.1

References


[ 1 ] Bug #2342285 - CVE-2024-52531 libsoup3: buffer overflow via UTF-8 conversion in soup_header_parse_param_list_strict [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2342285

Update Instructions

This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2025-42ee7772e3' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label

Name: libsoup3
Product: Fedora 41
Version: 3.6.4
Release: 1.fc41
Summary: Soup, an HTTP library implementation

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here