First published: Wed Jan 16 2019(Updated: )
URI_FUNC() in UriParse.c in uriparser before 0.9.1 has an out-of-bounds read (in uriParse*Ex* functions) for an incomplete URI with an IPv6 address containing an embedded IPv4 address, such as a "//[::44.1" address.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Uriparser Project Uriparser | <0.9.1 | |
Debian Debian Linux | =8.0 | |
Debian Debian Linux | =9.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2018-20721 is critical with a score of 9.8.
The affected software for CVE-2018-20721 includes uriparser before version 0.9.1 and Debian Linux versions 8.0 and 9.0.
The Common Weakness Enumeration (CWE) for CVE-2018-20721 is CWE-125.
To fix CVE-2018-20721, it is recommended to update uriparser to version 0.9.1 or later and apply the necessary patches for Debian Linux.
More information about CVE-2018-20721 can be found in the ChangeLog of uriparser, the GitHub commit, and the Debian Linux LTS announcement.