CVE-2018-20721
Summary
| CVE | CVE-2018-20721 |
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2019-01-16 14:29:00 UTC |
| Updated | 2021-12-16 19:01:00 UTC |
| Description | URI_FUNC() in UriParse.c in uriparser before 0.9.1 has an out-of-bounds read (in uriParse*Ex* functions) for an incomplete URI with an IPv6 address containing an embedded IPv4 address, such as a "//[::44.1" address. |
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|
| Fix uriParse*Ex* out-of-bounds read · uriparser/uriparser@cef2502 · GitHub |
CONFIRM |
github.com |
Patch, Third Party Advisory |
| [SECURITY] [DLA 1682-1] uriparser security update |
MLIST |
lists.debian.org |
Third Party Advisory |
| uriparser/ChangeLog at master · uriparser/uriparser · GitHub |
CONFIRM |
github.com |
Release Notes, Third Party Advisory |
| [SECURITY] [DLA 2834-1] uriparser security update |
MLIST |
lists.debian.org |
|
| CVE Program record |
CVE.ORG |
www.cve.org |
canonical |
| NVD vulnerability detail |
NVD |
nvd.nist.gov |
canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 178923 Debian Security Update for uriparser (DLA 2834-1)
- 198594 Ubuntu Security Notification for uriparser Vulnerabilities (USN-5172-1)