First published: Fri Nov 06 2020(Updated: )
raptor_xml_writer_start_element_common in raptor_xml_writer.c in Raptor RDF Syntax Library 2.0.15 miscalculates the maximum nspace declarations for the XML writer, leading to heap-based buffer overflows (sometimes seen in raptor_qname_format_as_xml).
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
debian/raptor2 | 2.0.14-1.1~deb10u2 2.0.14-1.1~deb10u1 2.0.14-1.2 2.0.15-4 2.0.16-3 | |
Librdf Raptor Rdf Syntax Library | =2.0.15 | |
Debian Debian Linux | =9.0 | |
Debian Debian Linux | =10.0 | |
Fedoraproject Fedora | =31 | |
Fedoraproject Fedora | =32 | |
Fedoraproject Fedora | =33 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID is CVE-2017-18926.
The title of the vulnerability is 'raptor_xml_writer_start_element_common in raptor_xml_writer.c in Raptor RDF Syntax Library 2.0.15'.
The severity of CVE-2017-18926 is high with a severity value of 7.1.
The affected software includes Raptor RDF Syntax Library 2.0.15, Debian Debian Linux 9.0 and 10.0, and Fedoraproject Fedora 31, 32, and 33.
To fix CVE-2017-18926, update the affected Raptor RDF Syntax Library version to 2.0.16-3 or apply the corresponding security patches provided by the software vendor.