CVE-2024-52530
Publication date 11 November 2024
Last updated 27 November 2024
Ubuntu priority
GNOME libsoup before 3.6.0 allows HTTP request smuggling in some configurations because '\0' characters at the end of header names are ignored, i.e., a "Transfer-Encoding\0: chunked" header is treated the same as a "Transfer-Encoding: chunked" header.
Status
Package | Ubuntu Release | Status |
---|---|---|
libsoup2.4 | 24.10 oracular |
Fixed 2.74.3-7ubuntu0.1
|
24.04 LTS noble |
Fixed 2.74.3-6ubuntu1.1
|
|
22.04 LTS jammy |
Fixed 2.74.2-3ubuntu0.1
|
|
20.04 LTS focal |
Fixed 2.70.0-1ubuntu0.1
|
|
18.04 LTS bionic |
Fixed 2.62.1-1ubuntu0.4+esm1
|
|
16.04 LTS xenial |
Needs evaluation
|
|
libsoup3 | 24.10 oracular |
Not affected
|
24.04 LTS noble |
Fixed 3.4.4-5ubuntu0.1
|
|
22.04 LTS jammy |
Fixed 3.0.7-0ubuntu1+esm1
|
|
20.04 LTS focal | Not in release |
Get expanded security coverage with Ubuntu Pro
Reduce your average CVE exposure time from 98 days to 1 day with expanded CVE patching, ten-years security maintenance and optional support for the full stack of open-source applications. Free for personal use.
Get Ubuntu ProReferences
Related Ubuntu Security Notices (USN)
- USN-7127-1
- libsoup3 vulnerabilities
- 27 November 2024
- USN-7126-1
- libsoup vulnerabilities
- 27 November 2024