Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2024-34402

Опубликовано: 03 мая 2024
Источник: redhat
CVSS3: 5.5
EPSS Низкий

Описание

An issue was discovered in uriparser through 0.9.7. ComposeQueryEngine in UriQuery.c has an integer overflow via long keys or values, with a resultant buffer overflow.

An integer overflow issue was found in Uriparser in the ComposeQueryEngine() function in UriQuery.c. This function computes the space needed for composing a query string. However, it encounters an integer overflow issue when handling large key or value lengths, potentially leading to incorrect memory allocations or operations due to malformed size calculations. This flaw allows attackers to crash the application, resulting in a denial of service.

Отчет

We do not distribute this package in RHEL 8, 9, and 10. Additionally, RHEL 7 is no longer within the scope of our supported versions.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 7uriparserOut of support scope

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-190->CWE-120
https://bugzilla.redhat.com/show_bug.cgi?id=2278807uriparser: integer overflow via long keys or values in ComposeQueryEngine() in UriQuery.c

EPSS

Процентиль: 46%
0.00231
Низкий

5.5 Medium

CVSS3

Связанные уязвимости

CVSS3: 8.6
ubuntu
больше 1 года назад

An issue was discovered in uriparser through 0.9.7. ComposeQueryEngine in UriQuery.c has an integer overflow via long keys or values, with a resultant buffer overflow.

CVSS3: 8.6
nvd
больше 1 года назад

An issue was discovered in uriparser through 0.9.7. ComposeQueryEngine in UriQuery.c has an integer overflow via long keys or values, with a resultant buffer overflow.

CVSS3: 8.6
msrc
6 месяцев назад

Описание отсутствует

CVSS3: 8.6
debian
больше 1 года назад

An issue was discovered in uriparser through 0.9.7. ComposeQueryEngine ...

CVSS3: 8.6
github
больше 1 года назад

An issue was discovered in uriparser through 0.9.7. ComposeQueryEngine in UriQuery.c has an integer overflow via long keys or values, with a resultant buffer overflow.

EPSS

Процентиль: 46%
0.00231
Низкий

5.5 Medium

CVSS3