CVE-2021-46142: Use After Free
An issue was discovered in uriparser before 0.9.6. It performs invalid free operations in uriNormalizeSyntax.
Affected Software
Remediation
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is CVE-2021-46142?
CVE-2021-46142 is a vulnerability discovered in uriparser before version 0.9.6 that performs invalid free operations in uriNormalizeSyntax.
How severe is CVE-2021-46142?
CVE-2021-46142 has a severity value of 5.5, which is classified as medium severity.
Which software is affected by CVE-2021-46142?
The vulnerability affects uriparser versions 0.9.1-1+deb10u1, 0.9.4+dfsg-1+deb11u1, 0.9.7+dfsg-2, as well as some Fedora, Debian, and openSUSE distributions.
How can I fix CVE-2021-46142?
To fix CVE-2021-46142, update uriparser to version 0.9.6 or later.
Where can I find more information about CVE-2021-46142?
You can find more information about CVE-2021-46142 on the following references: - [Blog Post](https://blog.hartwork.org/posts/uriparser-096-with-security-fixes-released/) - [GitHub Issue](https://github.com/uriparser/uriparser/issues/122) - [GitHub Pull Request](https://github.com/uriparser/uriparser/pull/124)