PT-2024-4515 · Uriparser+6 · Uriparser+6

Hartwork

·

Published

2024-04-21

·

Updated

2025-08-12

·

CVE-2024-34402

CVSS v2.0

9.0

High

VectorAV:N/AC:L/Au:N/C:P/I:P/A:C
Name of the Vulnerable Software and Affected Versions: uriparser versions 0.9.7 and earlier
Description: An issue in the ComposeQueryEngine function of UriQuery.c in uriparser is related to an integer overflow, which can occur via long keys or values and result in a buffer overflow. This can potentially allow a remote attacker to execute arbitrary code or cause a denial of service.
Recommendations: For uriparser versions 0.9.7 and earlier, consider disabling the ComposeQueryEngine function in UriQuery.c as a temporary workaround until a patch is available. Restrict exposure to the vulnerable function to minimize the risk of exploitation. Apply available patches to fix the integer overflow issue. Limit the use of long keys or values in the affected function to prevent buffer overflow.

Fix

Integer Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

AZL-43227
AZL-43231
BDU:2024-05019
CVE-2024-34402
ECHO-F51B-8317-0219
OESA-2024-1534
OESA-2024-1690
OPENSUSE-SU-2024:13957-1
OPENSUSE-SU-2024_1860-1
SUSE-SU-2024:1860-1
USN-7356-1

Affected Products

Astra Linux
Debian
Linuxmint
Red Os
Suse
Ubuntu
Uriparser