QID 198594

Date Published: 2021-12-08

QID 198594: Ubuntu Security Notification for uriparser Vulnerabilities (USN-5172-1)

Uriparser mishandled certain input.
Uriparser incorrectly handled certain uris.

Note: The preceding description block is extracted directly from the security advisory. Using automation, we have attempted to clean and format it as much as possible without introducing additional issues.

an attacker could use this vulnerability to cause uriparser to crash or possibly execute arbitrary code. (
Cve-2018-19198, cve-2018-19199, cve-2018-19200).
An attacker could use this vulnerability to cause a crash or possibly leak sensitive information. (
Cve-2018-20721).

  • CVSS V3 rated as Critical - 9.8 severity.
  • CVSS V2 rated as High - 7.5 severity.
  • Solution
    Refer to Ubuntu security advisory USN-5172-1 for updates and patch information.
    Vendor References

    CVEs related to QID 198594

    Software Advisories
    Advisory ID Software Component Link
    USN-5172-1 Ubuntu Linux URL Logo ubuntu.com/security/notices/USN-5172-1