CVE-2018-19198: Critical severity Uriparser Project Uriparser vulnerability
An issue was discovered in uriparser before 0.9.0. UriQuery.c allows an out-of-bounds write via a uriComposeQuery or uriComposeQueryEx function because the '&' character is mishandled in certain contexts.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is CVE-2018-19198?
CVE-2018-19198 is a vulnerability discovered in uriparser before 0.9.0 that allows an out-of-bounds write via certain functions.
How severe is CVE-2018-19198?
CVE-2018-19198 has a severity rating of 9.8 (critical).
How does CVE-2018-19198 affect uriparser?
CVE-2018-19198 affects uriparser versions before 0.9.0.
How can CVE-2018-19198 be fixed?
To fix CVE-2018-19198, update uriparser to version 0.9.0 or later.
Where can I find more information about CVE-2018-19198?
You can find more information about CVE-2018-19198 in the references provided: [Red Hat Security Advisory](https://access.redhat.com/errata/RHSA-2019:2280), [uriparser ChangeLog](https://github.com/uriparser/uriparser/blob/uriparser-0.9.0/ChangeLog), [uriparser commit](https://github.com/uriparser/uriparser/commit/864f5d4c127def386dd5cc926ad96934b297f04e).