安全公告详情

NS-SA-2025-0122

2025-07-25 16:49:52

简介

important: jose/libsoup security update

严重级别

important

主题

An update for jose/libsoup is now available for NewStart CGSL MAIN 7.02.
NewStart Security has rated this update as having a security impact of important. A Common Vunlnerability Scoring System(CVSS)base score, which gives a detailed severity rating, is available for each vulnerability from the CVElink(s) in the References section.

详细描述

jose:
libsoup:


Security Fix(es):
jose: A flaw was found in the Jose package, where a large number of iterations used to derive the wrapping key for the PBKDF2 algorithm may lead to a denial of service. This flaw allows an attacker to set a large number of `PBKDF2' iterations, triggering an uncontrolled resource consumption that impacts the availability of the targeted application.(CVE-2023-50967)
jose: bugfix
libsoup: A flaw was found in the libsoup library. Decoding specially crafted UTF-8 input data with the soup_header_parse_param_list_strict function can cause a heap-based buffer overflow, potentially resulting in code execution and denial of service to applications linked to the library.(CVE-2024-52531)
libsoup: bugfix


Solution:
For details on how to apply this update, which includes the changes described in this advisory, refer to:
http://security.gd-linux.com/how_to_apply_patch.html
Remember the build tag is 7.02.03B8.

影响组件

  • jose
  • libsoup

影响产品

  • CGSL MAIN 7.02

更新包

{"fix":[{"product":"CGSL MAIN 7.02","pkgs":[{"binary":["libjose-13-1.zncgsl7.1.x86_64.rpm","jose-13-1.zncgsl7.1.x86_64.rpm"],"source":"jose-13-1.zncgsl7.1.src.rpm"},{"binary":["libsoup-2.74.3-1.zncgsl7.3.x86_64.rpm","libsoup-devel-2.74.3-1.zncgsl7.3.x86_64.rpm"],"source":"libsoup-2.74.3-1.zncgsl7.3.src.rpm"}]}]}

CVE

参考