PT-2024-4515 · Uriparser+6 · Uriparser+6
Hartwork
·
Published
2024-04-21
·
Updated
2025-08-12
·
CVE-2024-34402
CVSS v2.0
9.0
High
| Vector | AV:N/AC:L/Au:N/C:P/I:P/A:C |
Name of the Vulnerable Software and Affected Versions:
uriparser versions 0.9.7 and earlier
Description:
An issue in the ComposeQueryEngine function of UriQuery.c in uriparser is related to an integer overflow, which can occur via long keys or values and result in a buffer overflow. This can potentially allow a remote attacker to execute arbitrary code or cause a denial of service.
Recommendations:
For uriparser versions 0.9.7 and earlier, consider disabling the ComposeQueryEngine function in UriQuery.c as a temporary workaround until a patch is available. Restrict exposure to the vulnerable function to minimize the risk of exploitation. Apply available patches to fix the integer overflow issue. Limit the use of long keys or values in the affected function to prevent buffer overflow.
Fix
Integer Overflow
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Astra Linux
Debian
Linuxmint
Red Os
Suse
Ubuntu
Uriparser