Integer overflow in uriparser - CVE-2024-34403
Published: May 6, 2024
Vulnerability details
The vulnerability allows a remote attacker to execute arbitrary code on the target system.
The vulnerability exists due to integer overflow within the ComposeQueryMallocExMm() function in UriQuery.c. A remote attacker can pass specially crafted data to the application, trigger integer overflow and execute arbitrary code on the target system.
Successful exploitation of this vulnerability may result in complete compromise of vulnerable system.
Affected software
Fedora
Ubuntu
openEuler
liburiparser1 (Ubuntu package)
uriparser
uriparser-debuginfo
uriparser-debugsource
uriparser-devel
uriparser-help
How to mitigate CVE-2024-34403
liburiparser1 (Ubuntu package) - update to Ubuntu Pro
uriparser - update to 0.9.6-2
uriparser-debuginfo - update to 0.9.6-2
uriparser-debugsource - update to 0.9.6-2
uriparser-devel - update to 0.9.6-2
uriparser-help - update to 0.9.6-2
uriparser - addressed in versions 0.9.8-1.fc38, 0.9.8-1.fc39, 0.9.8-1.fc40, 0.9.8-2.el8, 0.9.8-2.el9, 0.9.8-2.el10_1
External References
Related Security Bulletins
- Two integer overflow vulnerabilities in uriparser
- Fedora 40 update for uriparser
- Fedora 39 update for uriparser
- Fedora 38 update for uriparser
- openEuler update for uriparser
- openEuler 22.03 LTS SP3 update for uriparser
- Ubuntu update for uriparser
- Fedora EPEL 9 update for uriparser
- Fedora EPEL 10.1 update for uriparser
- Fedora EPEL 8 update for uriparser