openSUSE-SU-2019:0171-1
Dashboard / Vulnerabilities / openSUSE-SU-2019:0171-1
openSUSE-SU-2019:0171-1
Summary: Security update for uriparser
Details: This update for uriparser fixes the following issues: Security issues fixed: - CVE-2018-20721: Fixed an out-of-bounds read for incomplete URIs with IPv6 addresses with embedded IPv4 address (bsc#1122193). - CVE-2018-19198: Fixed an out-of-bounds write that was possible via the uriComposeQuery* or uriComposeQueryEx* function (bsc#1115722). - CVE-2018-19199: Fixed an integer overflow caused by an unchecked multiplication via the uriComposeQuery* or uriComposeQueryEx* function (bsc#1115723). - CVE-2018-19200: Fixed a operation attempted on NULL input via a uriResetUri* function (bsc#1115724). This update was imported from the SUSE:SLE-15:Update update project. This update was imported from the openSUSE:Leap:15.0:Update update project.
References: https://lists.opensuse.org/archives/list/[email protected]/thread/N2HDQPAE2BYVHUDZFAEARC2MXGC7KBVR/#N2HDQPAE2BYVHUDZFAEARC2MXGC7KBVR, https://bugzilla.suse.com/1115722, https://bugzilla.suse.com/1115723, https://bugzilla.suse.com/1115724, https://bugzilla.suse.com/1122193, https://www.suse.com/security/cve/CVE-2018-19198, https://www.suse.com/security/cve/CVE-2018-19199, https://www.suse.com/security/cve/CVE-2018-19200, https://www.suse.com/security/cve/CVE-2018-20721
Affected packages
Package
Name: uriparser
Purl: pkg:rpm/suse/uriparser&distro=SUSE%20Package%20Hub%2015
Affected ranges
Type: ECOSYSTEM
Events:
