CVE-2021-46141
published 2022-01-06CVE-2021-46141: An issue was discovered in uriparser before 0.9.6. It performs invalid free operations in uriFreeUriMembers and uriMakeOwner.
PriorityP419medium5.5CVSS 3.1
AVLACLPRNUIRSUCNINAH
EPSS
1.13%
62.8th percentile
An issue was discovered in uriparser before 0.9.6. It performs invalid free operations in uriFreeUriMembers and uriMakeOwner.
Affected
18 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| debian | uriparser | < uriparser 0.9.6+dfsg-1 (bookworm) | uriparser 0.9.6+dfsg-1 (bookworm) |
| fedoraproject | extra_packages_for_enterprise_linux | — | — |
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
| opensuse | backports | — | — |
| opensuse | leap | — | — |
| uriparser_project | uriparser | < 0.9.6 | 0.9.6 |
| uriparser_project | uriparser | >= 0 < 0.9.4+dfsg-1+deb11u1 | 0.9.4+dfsg-1+deb11u1 |
| uriparser_project | uriparser | >= 0 < 0.9.6+dfsg-1 | 0.9.6+dfsg-1 |
| uriparser_project | uriparser | >= 0 < 0.9.6+dfsg-1 | 0.9.6+dfsg-1 |
| uriparser_project | uriparser | >= 0 < 0.9.6+dfsg-1 | 0.9.6+dfsg-1 |
| uriparser_project | uriparser | >= 0 < 0.8.4-1+deb9u2ubuntu0.1 | 0.8.4-1+deb9u2ubuntu0.1 |
| uriparser_project | uriparser | >= 0 < 0.7.5-1ubuntu2+esm3 | 0.7.5-1ubuntu2+esm3 |
| uriparser_project | uriparser | >= 0 < 0.8.4-1ubuntu0.16.04.1~esm3 | 0.8.4-1ubuntu0.16.04.1~esm3 |
| uriparser_project | uriparser | >= 0 < 0.9.3-2ubuntu0.1~esm2 | 0.9.3-2ubuntu0.1~esm2 |
CVSS provenance
nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:N/I:N/A:P
osv5.5MEDIUM
vendor_debian5.5MEDIUM
vendor_redhat5.5MEDIUM
vendor_ubuntu5.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
uriparser vulnerabilities
vendor_ubuntu·2022-07-18·CVSS 5.5
CVE-2021-46142 [MEDIUM] uriparser vulnerabilities
Title: uriparser vulnerabilities
Summary: uriparser could be made to crash if it received specially crafted
input.
USN-5256-1 fixed several vulnerabilities in uriparser. This update provides
the corresponding update for Ubuntu 14.04 ESM, Ubuntu 16.04 ESM and
Ubuntu 20.04 ESM.
Original advisory details:
It was discovered that uriparser incorrectly handled certain memory operations.
An attacker could use this to cause a denial of service.
(CVE-2021-46141, CVE-2021-46142)
Instructions: In general, a standard system update will make all the necessary changes.
Ubuntu
uriparser vulnerabilities
vendor_ubuntu·2022-07-13·CVSS 5.5
CVE-2021-46141 [MEDIUM] uriparser vulnerabilities
Title: uriparser vulnerabilities
Summary: uriparser could be made to crash if it received specially crafted
input.
It was discovered that uriparser incorrectly handled certain memory operations.
An attacker could use this to cause a denial of service.
(CVE-2021-46141, CVE-2021-46142)
Instructions: In general, a standard system update will make all the necessary changes.
Red Hat
uriparser: Invalid free operations in uriFreeUriMembers and uriMakeOwner
vendor_redhat·2022-01-03·CVSS 5.5
CVE-2021-46141 [MEDIUM] CWE-401 uriparser: Invalid free operations in uriFreeUriMembers and uriMakeOwner
uriparser: Invalid free operations in uriFreeUriMembers and uriMakeOwner
An issue was discovered in uriparser before 0.9.6. It performs invalid free operations in uriFreeUriMembers and uriMakeOwner.
An Invalid pointer operations flaw was found in uriparser. An attacker with local network access could pass a specially crafted unknown input causing that application to crash.
Package: uriparser (Red Hat Enterprise Linux 7) - Out of support scope
Debian
CVE-2021-46141: uriparser - An issue was discovered in uriparser before 0.9.6. It performs invalid free oper...
vendor_debian·2021·CVSS 5.5
CVE-2021-46141 [MEDIUM] CVE-2021-46141: uriparser - An issue was discovered in uriparser before 0.9.6. It performs invalid free oper...
An issue was discovered in uriparser before 0.9.6. It performs invalid free operations in uriFreeUriMembers and uriMakeOwner.
Scope: local
bookworm: resolved (fixed in 0.9.6+dfsg-1)
bullseye: resolved (fixed in 0.9.4+dfsg-1+deb11u1)
forky: resolved (fixed in 0.9.6+dfsg-1)
sid: resolved (fixed in 0.9.6+dfsg-1)
trixie: resolved (fixed in 0.9.6+dfsg-1)
OSV
uriparser vulnerabilities
osv·2022-07-18·CVSS 5.5
CVE-2021-46141 [MEDIUM] uriparser vulnerabilities
uriparser vulnerabilities
USN-5256-1 fixed several vulnerabilities in uriparser. This update provides
the corresponding update for Ubuntu 14.04 ESM, Ubuntu 16.04 ESM and
Ubuntu 20.04 ESM.
Original advisory details:
It was discovered that uriparser incorrectly handled certain memory operations.
An attacker could use this to cause a denial of service.
(CVE-2021-46141, CVE-2021-46142)
OSV
uriparser vulnerabilities
osv·2022-07-13·CVSS 5.5
CVE-2021-46141 [MEDIUM] uriparser vulnerabilities
uriparser vulnerabilities
It was discovered that uriparser incorrectly handled certain memory operations.
An attacker could use this to cause a denial of service.
(CVE-2021-46141, CVE-2021-46142)
GHSA
GHSA-h7v5-6w5c-368p: An issue was discovered in uriparser before 0
ghsa_unreviewed·2022-01-07
CVE-2021-46141 [MEDIUM] CWE-416 GHSA-h7v5-6w5c-368p: An issue was discovered in uriparser before 0
An issue was discovered in uriparser before 0.9.6. It performs invalid free operations in uriFreeUriMembers and uriMakeOwner.
OSV
CVE-2021-46141: An issue was discovered in uriparser before 0
osv·2022-01-06·CVSS 5.5
CVE-2021-46141 [MEDIUM] CVE-2021-46141: An issue was discovered in uriparser before 0
An issue was discovered in uriparser before 0.9.6. It performs invalid free operations in uriFreeUriMembers and uriMakeOwner.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://blog.hartwork.org/posts/uriparser-096-with-security-fixes-released/https://github.com/uriparser/uriparser/issues/121https://github.com/uriparser/uriparser/pull/124https://lists.debian.org/debian-lts-announce/2022/01/msg00029.htmlhttps://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/MO6T7WA27H7K3WI2AXUAGPWBGK4HM65D/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/YGIJTDNEMU2V4H3JJBQVKBRHU5GBQKG2/https://www.debian.org/security/2022/dsa-5063https://blog.hartwork.org/posts/uriparser-096-with-security-fixes-released/https://github.com/uriparser/uriparser/issues/121https://github.com/uriparser/uriparser/pull/124https://lists.debian.org/debian-lts-announce/2022/01/msg00029.htmlhttps://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/MO6T7WA27H7K3WI2AXUAGPWBGK4HM65D/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/YGIJTDNEMU2V4H3JJBQVKBRHU5GBQKG2/https://www.debian.org/security/2022/dsa-5063
2022-01-06
Published