CVE-2024-57823: Integer Underflow
Published Jan 10, 2025
·Updated
In Raptor RDF Syntax Library through 2.0.16, there is an integer underflow when normalizing a URI with the turtle parser in raptorurinormalizepath().
Affected Software
3 affected componentsFixes available
Raptor RDF Syntax Library Raptor RDF Syntax Library<=2.0.16
Librdf Raptor Rdf Syntax Library<=2.0.16
debian/raptor2<=2.0.14-1.2
2.0.14-1.2+deb11u12.0.15-4+deb12u12.0.16-6
Event History
Jan 10, 2025
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·01:15 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·01:15 PM
Affected Software
Data Sourced
via Red Hat·02:01 PM
DescriptionSeverityAffected Software
Mar 3, 2025
Data Sourced
via Ubuntu·06:26 PM
RemedyDescriptionSeverityAffected Software
Nov 3, 2025
Data Sourced
via Debian·05:43 PM
DescriptionAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2024-57823?
CVE-2024-57823 is classified as a medium severity vulnerability due to the potential for an integer underflow exploit.
2
How do I fix CVE-2024-57823?
To fix CVE-2024-57823, update the Raptor RDF Syntax Library to version 2.0.17 or later.
3
What causes CVE-2024-57823?
CVE-2024-57823 is caused by an integer underflow that occurs during URI normalization in the turtle parser.
4
Which versions are affected by CVE-2024-57823?
CVE-2024-57823 affects all versions of Raptor RDF Syntax Library up to and including 2.0.16.
5
Is there a workaround for CVE-2024-57823?
Currently, there is no known workaround for CVE-2024-57823 other than upgrading to the latest version.