Описание
Security update for uriparser
This update for uriparser fixes the following issues
- CVE-2026-42371: numeric truncation in text range comparison when an application accepts URIs with a length in gigabytes (bsc#1262999).
- CVE-2026-44927: truncation of
ptrdiff_ttointin various places (bsc#1264578). - CVE-2026-44928: function family
EqualsUrican misclassify two unequal URIs as equal (bsc#1264579).
Список пакетов
openSUSE Leap 16.0
liburiparser1-0.9.8-160000.5.1
uriparser-0.9.8-160000.5.1
uriparser-devel-0.9.8-160000.5.1
uriparser-doc-0.9.8-160000.5.1
Ссылки
- SUSE Security Ratings
- SUSE Bug 1262999
- SUSE Bug 1264578
- SUSE Bug 1264579
- SUSE CVE CVE-2026-42371 page
- SUSE CVE CVE-2026-44927 page
- SUSE CVE CVE-2026-44928 page
Описание
uriparser before 1.0.1 has numeric truncation in text range comparison, if an application accepts URIs with a length in gigabytes.
Затронутые продукты
openSUSE Leap 16.0:liburiparser1-0.9.8-160000.5.1
openSUSE Leap 16.0:uriparser-0.9.8-160000.5.1
openSUSE Leap 16.0:uriparser-devel-0.9.8-160000.5.1
openSUSE Leap 16.0:uriparser-doc-0.9.8-160000.5.1
Ссылки
- CVE-2026-42371
- SUSE Bug 1262999
Описание
In uriparser before 1.0.2, there is pointer difference truncation to int in various places.
Затронутые продукты
openSUSE Leap 16.0:liburiparser1-0.9.8-160000.5.1
openSUSE Leap 16.0:uriparser-0.9.8-160000.5.1
openSUSE Leap 16.0:uriparser-devel-0.9.8-160000.5.1
openSUSE Leap 16.0:uriparser-doc-0.9.8-160000.5.1
Ссылки
- CVE-2026-44927
- SUSE Bug 1264578
Описание
In uriparser before 1.0.2, the function family EqualsUri can misclassify two unequal URIs as equal.
Затронутые продукты
openSUSE Leap 16.0:liburiparser1-0.9.8-160000.5.1
openSUSE Leap 16.0:uriparser-0.9.8-160000.5.1
openSUSE Leap 16.0:uriparser-devel-0.9.8-160000.5.1
openSUSE Leap 16.0:uriparser-doc-0.9.8-160000.5.1
Ссылки
- CVE-2026-44928
- SUSE Bug 1264579