• Bug#1102213: libsoup2.4: CVE-2025-32051

    From Salvatore Bonaccorso@21:1/5 to All on Sun Apr 6 14:30:01 2025
    Source: libsoup2.4
    Version: 2.74.3-9
    Severity: important
    Tags: security upstream
    Forwarded: https://gitlab.gnome.org/GNOME/libsoup/-/issues/401
    X-Debbugs-Cc: carnil@debian.org, Debian Security Team <team@security.debian.org>

    Hi,

    The following vulnerability was published for libsoup2.4.

    CVE-2025-32051[0]:
    | A flaw was found in libsoup. The libsoup soup_uri_decode_data_uri()
    | function may crash when processing malformed data URI. This flaw
    | allows an attacker to cause a denial of service (DoS).

    The code was refactored in 2.99.1 with 737eef099ca1 ("Replace SoupURI
    with GUri") upstream but the same underlying code seems present in the
    original implementation, but I'm not 100% certain. Please
    double-check.

    If you fix the vulnerability please also make sure to include the
    CVE (Common Vulnerabilities & Exposures) id in your changelog entry.

    For further information see:

    [0] https://security-tracker.debian.org/tracker/CVE-2025-32051
    https://www.cve.org/CVERecord?id=CVE-2025-32051
    [1] https://gitlab.gnome.org/GNOME/libsoup/-/issues/401

    Please adjust the affected versions in the BTS as needed.

    Regards,
    Salvatore

    --- SoupGate-Win32 v1.05
    * Origin: fsxNet Usenet Gateway (21:1/5)
  • From Sylvain Beucler@21:1/5 to carnil@debian.org on Tue Apr 8 23:20:01 2025
    Hi,

    On Sun, 06 Apr 2025 14:25:36 +0200 Salvatore Bonaccorso
    <carnil@debian.org> wrote:
    The code was refactored in 2.99.1 with 737eef099ca1 ("Replace SoupURI
    with GUri") upstream but the same underlying code seems present in the original implementation, but I'm not 100% certain. Please
    double-check.
    AFAICS the code was introduced (in SoupURI form) along with the 'soup_uri_decode_data_uri' function a bit before that in https://gitlab.gnome.org/GNOME/libsoup/-/commit/9f42c7b8dc1d099b1464070ca993189bf7a3cdd0
    (still in 2.99.1).

    I believe libsoup2.4 is <not-affected>.

    Cheers!
    Sylvain Beucler
    Debian LTS Team

    --- SoupGate-Win32 v1.05
    * Origin: fsxNet Usenet Gateway (21:1/5)