Null pointer dereference in uriparser - CVE-2018-19200
Published: November 15, 2018
Vulnerability details
The vulnerability allows a local attacker to cause DoS condition on the target system.
The vulnerability exists in the uriResetUri* function, as defined in the UriCommon.c source code file due to the allowance of operations on a NULL input. A local attacker can send a specially request that submits malicious input, trigger NULL pointer dereference to cause a DoS condition.
Affected software
Opensuse
Ubuntu
Fedora
liburiparser1 (Ubuntu package)
mingw-uriparser
uriparser
How to mitigate CVE-2018-19200
liburiparser1 (Ubuntu package) - update to 0.8.4-1+deb9u2build0.18.04.1
mingw-uriparser - addressed in versions 0.9.0-1.fc28, 0.9.0-1.fc29
uriparser - addressed in versions 0.9.0-1.fc28, 0.9.0-1.fc29