Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2024-57823

Опубликовано: 10 янв. 2025
Источник: redhat
CVSS3: 7.3
EPSS Низкий

Описание

In Raptor RDF Syntax Library through 2.0.16, there is an integer underflow when normalizing a URI with the turtle parser in raptor_uri_normalize_path().

A flaw was found in the Raptor RDF syntax library (librdf). An integer underflow condition may be triggered when normalizing a URI with the turtle parser. This issue could cause memory corruption or an application crash, leading to a denial of service or other undefined behavior.

Отчет

This vulnerability in the Raptor RDF syntax library (librdf) ios marked as important severity rather than moderate due to the potential for memory corruption resulting from the integer underflow condition. Memory corruption can lead to application crashes, creating a reliable vector for denial-of-service (DoS) attacks, and, in certain cases, could be exploited to achieve arbitrary code execution, depending on how memory is manipulated. Given that the Turtle parser is commonly used for processing external RDF data, the vulnerability increases the attack surface for applications that handle untrusted or user-supplied input.

Меры по смягчению последствий

Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 6raptorOut of support scope
Red Hat Enterprise Linux 7 Extended Lifecycle Supportraptor2FixedRHSA-2025:031914.01.2025
Red Hat Enterprise Linux 8raptor2FixedRHSA-2025:031414.01.2025
Red Hat Enterprise Linux 8.2 Advanced Update Supportraptor2FixedRHSA-2025:031514.01.2025
Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Supportraptor2FixedRHSA-2025:031314.01.2025
Red Hat Enterprise Linux 8.4 Telecommunications Update Serviceraptor2FixedRHSA-2025:031314.01.2025
Red Hat Enterprise Linux 8.4 Update Services for SAP Solutionsraptor2FixedRHSA-2025:031314.01.2025
Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Supportraptor2FixedRHSA-2025:032615.01.2025
Red Hat Enterprise Linux 8.6 Telecommunications Update Serviceraptor2FixedRHSA-2025:032615.01.2025
Red Hat Enterprise Linux 8.6 Update Services for SAP Solutionsraptor2FixedRHSA-2025:032615.01.2025

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-191
https://bugzilla.redhat.com/show_bug.cgi?id=2336921raptor: integer underflow when normalizing a URI with the turtle parser

EPSS

Процентиль: 8%
0.00034
Низкий

7.3 High

CVSS3

Связанные уязвимости

CVSS3: 9.3
ubuntu
5 месяцев назад

In Raptor RDF Syntax Library through 2.0.16, there is an integer underflow when normalizing a URI with the turtle parser in raptor_uri_normalize_path().

CVSS3: 9.3
nvd
5 месяцев назад

In Raptor RDF Syntax Library through 2.0.16, there is an integer underflow when normalizing a URI with the turtle parser in raptor_uri_normalize_path().

CVSS3: 9.3
debian
5 месяцев назад

In Raptor RDF Syntax Library through 2.0.16, there is an integer under ...

CVSS3: 9.3
redos
3 месяца назад

Уязвимость raptor2

rocky
5 месяцев назад

Important: raptor2 security update

EPSS

Процентиль: 8%
0.00034
Низкий

7.3 High

CVSS3

Уязвимость CVE-2024-57823