fyi, the libsoup2.4 packages do not appear to be affected; it makes use of the glib base64 modules (which are actually vulnerable themselves, but that's a separate bug).