Lucene search

K
amazonAmazonALAS-2024-2546
HistoryMay 23, 2024 - 10:04 p.m.

Medium: uriparser

2024-05-2322:04:00
alas.aws.amazon.com
7
uriparser
integer overflow
buffer overflow
cve-2024-34402
cve-2024-34403
amazon linux 2
update
red hat
mitre
unix

CVSS3

8.6

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

LOW

Integrity Impact

LOW

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H

AI Score

7.3

Confidence

High

EPSS

0

Percentile

10.3%

Issue Overview:

An issue was discovered in uriparser through 0.9.7. ComposeQueryEngine in UriQuery.c has an integer overflow via long keys or values, with a resultant buffer overflow. (CVE-2024-34402)

An issue was discovered in uriparser through 0.9.7. ComposeQueryMallocExMm in UriQuery.c has an integer overflow via a long string. (CVE-2024-34403)

Affected Packages:

uriparser

Note:

This advisory is applicable to Amazon Linux 2 (AL2) Core repository. Visit this FAQ section for the difference between AL2 Core and AL2 Extras advisories.

Issue Correction:
Run yum update uriparser to update your system.

New Packages:

aarch64:  
    uriparser-0.7.5-10.amzn2.0.3.aarch64  
    uriparser-devel-0.7.5-10.amzn2.0.3.aarch64  
    uriparser-debuginfo-0.7.5-10.amzn2.0.3.aarch64  
  
i686:  
    uriparser-0.7.5-10.amzn2.0.3.i686  
    uriparser-devel-0.7.5-10.amzn2.0.3.i686  
    uriparser-debuginfo-0.7.5-10.amzn2.0.3.i686  
  
src:  
    uriparser-0.7.5-10.amzn2.0.3.src  
  
x86_64:  
    uriparser-0.7.5-10.amzn2.0.3.x86_64  
    uriparser-devel-0.7.5-10.amzn2.0.3.x86_64  
    uriparser-debuginfo-0.7.5-10.amzn2.0.3.x86_64  

Additional References

Red Hat: CVE-2024-34402, CVE-2024-34403

Mitre: CVE-2024-34402, CVE-2024-34403

CVSS3

8.6

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

LOW

Integrity Impact

LOW

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H

AI Score

7.3

Confidence

High

EPSS

0

Percentile

10.3%