CVE-2024-52531

Severity CVSS v4.0:
Pending analysis
Type:
CWE-787 Out-of-bounds Write
Publication date:
11/11/2024
Last modified:
03/11/2025

Description

GNOME libsoup before 3.6.1 allows a buffer overflow in applications that perform conversion to UTF-8 in soup_header_parse_param_list_strict. There is a plausible way to reach this remotely via soup_message_headers_get_content_type (e.g., an application may want to retrieve the content type of a request or response).

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:gnome:libsoup:*:*:*:*:*:*:*:* 3.6.1 (excluding)