First published: Mon Nov 12 2018(Updated: )
An issue was discovered in uriparser before 0.9.0. UriQuery.c allows an out-of-bounds write via a uriComposeQuery* or uriComposeQueryEx* function because the '&' character is mishandled in certain contexts.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
redhat/uriparser | <0.9.0 | 0.9.0 |
Uriparser Project Uriparser | <0.9.0 | |
Debian Debian Linux | =8.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-19198 is a vulnerability discovered in uriparser before 0.9.0 that allows an out-of-bounds write via certain functions.
CVE-2018-19198 has a severity rating of 9.8 (critical).
CVE-2018-19198 affects uriparser versions before 0.9.0.
To fix CVE-2018-19198, update uriparser to version 0.9.0 or later.
You can find more information about CVE-2018-19198 in the references provided: [Red Hat Security Advisory](https://access.redhat.com/errata/RHSA-2019:2280), [uriparser ChangeLog](https://github.com/uriparser/uriparser/blob/uriparser-0.9.0/ChangeLog), [uriparser commit](https://github.com/uriparser/uriparser/commit/864f5d4c127def386dd5cc926ad96934b297f04e).