AVG-2794 log
| Package | uriparser |
| Status | Fixed |
| Severity | Medium |
| Type | denial of service |
| Affected | 0.9.5-1 |
| Fixed | 0.9.6-1 |
| Current | 0.9.9-1 [extra] |
| Ticket | None |
| Created | Wed Aug 3 21:07:54 2022 |
| Issue | Severity | Remote | Type | Description |
|---|---|---|---|---|
| CVE-2021-46142 | Medium | No | Denial of service | uriNormalizeSyntax may free stack memory in out-of-memory situation when handling URIs containing empty segments |
| CVE-2021-46141 | Medium | No | Denial of service | .hostText memory is not properly duped/freed in uriNormalizeSyntax, uriMakeOwner, uriFreeUriMembers for some URIs |
| References |
|---|
https://github.com/uriparser/uriparser/pull/124 https://github.com/uriparser/uriparser/commit/cd6070c92f3bab157139c35ff4841054afaa67ef |