Bug#1102213: libsoup2.4: CVE-2025-32051
Salvatore Bonaccorso
carnil at debian.org
Sun Apr 6 13:25:36 BST 2025
Source: libsoup2.4
Version: 2.74.3-9
Severity: important
Tags: security upstream
Forwarded: https://gitlab.gnome.org/GNOME/libsoup/-/issues/401
X-Debbugs-Cc: carnil at debian.org, Debian Security Team <team at security.debian.org>
Hi,
The following vulnerability was published for libsoup2.4.
CVE-2025-32051[0]:
| A flaw was found in libsoup. The libsoup soup_uri_decode_data_uri()
| function may crash when processing malformed data URI. This flaw
| allows an attacker to cause a denial of service (DoS).
The code was refactored in 2.99.1 with 737eef099ca1 ("Replace SoupURI
with GUri") upstream but the same underlying code seems present in the
original implementation, but I'm not 100% certain. Please
double-check.
If you fix the vulnerability please also make sure to include the
CVE (Common Vulnerabilities & Exposures) id in your changelog entry.
For further information see:
[0] https://security-tracker.debian.org/tracker/CVE-2025-32051
https://www.cve.org/CVERecord?id=CVE-2025-32051
[1] https://gitlab.gnome.org/GNOME/libsoup/-/issues/401
Please adjust the affected versions in the BTS as needed.
Regards,
Salvatore
More information about the pkg-gnome-maintainers
mailing list