USN-5172-2
Dashboard / Vulnerabilities / USN-5172-2
USN-5172-2
Summary: uriparser vulnerability
Details: USN-5172-1 fixed vulnerabilities in uriparser. This update provides the corresponding updates for Ubuntu 14.04 ESM and Ubuntu 16.04 ESM. Original advisory details: It was discovered that uriparser mishandled certain input. An attacker could use this vulnerability to cause uriparser to crash or possibly execute arbitrary code. (CVE-2018-19198, CVE-2018-19199, CVE-2018-19200) It was discovered that uriparser incorrectly handled certain URIs. An attacker could use this vulnerability to cause a crash or possibly leak sensitive information. (CVE-2018-20721)
References: https://ubuntu.com/security/notices/USN-5172-2, https://ubuntu.com/security/CVE-2018-19198, https://ubuntu.com/security/CVE-2018-19199, https://ubuntu.com/security/CVE-2018-19200, https://ubuntu.com/security/CVE-2018-20721
Affected packages
Package
Name: uriparser
Purl: pkg:deb/ubuntu/uriparser?arch=source&distro=trusty%2Fesm
Affected ranges
Type: ECOSYSTEM
Events:
