Out-of-bounds write in uriparser - CVE-2018-19198

 

Out-of-bounds write in uriparser - CVE-2018-19198

Published: November 15, 2018


Vulnerability identifier: #VU15910
CSH Severity: Low
CVSS v4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2018-19198
CWE-ID: CWE-787
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local attacker to cause DoS condition or execute arbitrary code on the target system.

The vulnerability exists due to out-of-bounds write in the uriComposeQuery* and uriComposeQueryEx* functions, as defined in the UriQuery.csource code file. A local attacker can send a specially request that submits malicious input, trigger memory corruption to cause a DoS condition or execute arbitrary code with elevated privileges.

Successful exploitation of the vulnerability may result in system compromise.


Affected software

uriparser
Red Hat Enterprise Linux Server
Red Hat Enterprise Linux Workstation
Red Hat Enterprise Linux Desktop
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for Scientific Computing
Opensuse
Ubuntu
Fedora
liburiparser1 (Ubuntu package)
mingw-uriparser
uriparser

How to mitigate CVE-2018-19198

Update to version 0.9.

uriparser - update to 0.9
liburiparser1 (Ubuntu package) - update to 0.8.4-1+deb9u2build0.18.04.1
mingw-uriparser - addressed in versions 0.9.0-1.fc28, 0.9.0-1.fc29
uriparser - addressed in versions 0.9.0-1.fc28, 0.9.0-1.fc29

External References

Related Security Bulletins