CVE-2024-34402: Integer Overflow
Published May 3, 2024
·Updated
An issue was discovered in uriparser through 0.9.7. ComposeQueryEngine in UriQuery.c has an integer overflow via long keys or values, with a resultant buffer overflow.
Affected Software
6 affected componentsFixes available
debian/uriparser<=0.9.4+dfsg-1+deb11u1, <=0.9.7+dfsg-2
0.9.8+dfsg-2
uriparser uriparser>=0.9.7
Uriparser Project Uriparser<=0.9.7
Fedoraproject Fedora=38
Fedoraproject Fedora=39
Fedoraproject Fedora=40
Event History
May 3, 2024
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·01:15 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·01:15 AM
Affected Software
Mar 19, 2025
Data Sourced
via Launchpad·02:57 AM
Description
Mar 23, 2025
Data Sourced
via Ubuntu·02:56 AM
RemedyDescriptionSeverityAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2024-34402?
CVE-2024-34402 is considered a high severity vulnerability due to its potential for causing buffer overflows.
2
How do I fix CVE-2024-34402?
To mitigate CVE-2024-34402, update to a patched version of uriparser that addresses the integer overflow issue.
3
What type of vulnerability is CVE-2024-34402?
CVE-2024-34402 is characterized as a buffer overflow vulnerability resulting from an integer overflow.
4
Which versions of uriparser are affected by CVE-2024-34402?
CVE-2024-34402 affects uriparser version 0.9.7 and potentially earlier versions.
5
What impact does CVE-2024-34402 have on systems?
CVE-2024-34402 can lead to arbitrary code execution or application crashes due to its buffer overflow.