REDHAT-BUG-2336921: High severity redland libraptor vulnerability
Published Jan 10, 2025
·Updated
In Raptor RDF Syntax Library through 2.0.16, there is an integer underflow when normalizing a URI with the turtle parser in raptorurinormalizepath().
Affected Software
1 affected component
Raptor RDF Syntax Library<=2.0.16
Event History
Jan 10, 2025
Data Sourced
via Red Hat·02:01 PM
DescriptionSeverityAffected Software
Frequently Asked Questions
1
What is the severity of REDHAT-BUG-2336921?
The severity of REDHAT-BUG-2336921 is considered high due to potential security implications related to integer underflows.
2
How do I fix REDHAT-BUG-2336921?
To fix REDHAT-BUG-2336921, you should upgrade the Raptor RDF Syntax Library to version 2.0.17 or later.
3
What versions are affected by REDHAT-BUG-2336921?
REDHAT-BUG-2336921 affects Raptor RDF Syntax Library versions up to and including 2.0.16.
4
What kind of vulnerability is REDHAT-BUG-2336921?
REDHAT-BUG-2336921 is an integer underflow vulnerability found in the URI normalization process of the turtle parser.
5
Is there a workaround for REDHAT-BUG-2336921?
There is no official workaround for REDHAT-BUG-2336921; the recommended action is to upgrade to a fixed version.