fyi, the libsoup2.4 packages do not appear to be affected; it makes use of the glib base64 modules (which are actually vulnerable themselves, but that's a separate bug).
-- To UNSUBSCRIBE, email to debian-bugs-rc-requ...@lists.debian.org with a subject of "unsubscribe". Trouble? Contact listmas...@lists.debian.org