AVG-2794 log
Package | uriparser |
Status | Fixed |
Severity | Medium |
Type | denial of service |
Affected | 0.9.5-1 |
Fixed | 0.9.6-1 |
Current | 0.9.8-1 [extra] |
Ticket | None |
Created | Wed Aug 3 21:07:54 2022 |
Issue | Severity | Remote | Type | Description |
---|---|---|---|---|
CVE-2021-46142 | Medium | No | Denial of service | uriNormalizeSyntax may free stack memory in out-of-memory situation when handling URIs containing empty segments |
CVE-2021-46141 | Medium | No | Denial of service | .hostText memory is not properly duped/freed in uriNormalizeSyntax, uriMakeOwner, uriFreeUriMembers for some URIs |
References |
---|
https://github.com/uriparser/uriparser/pull/124 https://github.com/uriparser/uriparser/commit/cd6070c92f3bab157139c35ff4841054afaa67ef |