cbcvebase.
CVE-2024-34402
published 2024-05-03

CVE-2024-34402: An issue was discovered in uriparser through 0.9.7. ComposeQueryEngine in UriQuery.c has an integer overflow via long keys or values, with a resultant buffer…

PriorityP346high8.6CVSS 3.1
AVNACLPRNUINSUCLILAH
EPSS
1.23%
65.6th percentile
An issue was discovered in uriparser through 0.9.7. ComposeQueryEngine in UriQuery.c has an integer overflow via long keys or values, with a resultant buffer overflow.

Affected

14 ranges
VendorProductVersion rangeFixed in
debianuriparser< uriparser 0.9.8+dfsg-1 (forky)uriparser 0.9.8+dfsg-1 (forky)
fedoraprojectfedora
fedoraprojectfedora
fedoraprojectfedora
msrcazl3_uriparser_0.9.8-3_on_azure_linux_3.0
uriparser_projecturiparser<= 0.9.7
uriparser_projecturiparser>= 0 < 0.9.8+dfsg-10.9.8+dfsg-1
uriparser_projecturiparser>= 0 < 0.9.8+dfsg-10.9.8+dfsg-1
uriparser_projecturiparser>= 0 < 0.7.5-1ubuntu2+esm40.7.5-1ubuntu2+esm4
uriparser_projecturiparser>= 0 < 0.8.4-1ubuntu0.16.04.1~esm40.8.4-1ubuntu0.16.04.1~esm4
uriparser_projecturiparser>= 0 < 0.8.4-1+deb9u2ubuntu0.1+esm10.8.4-1+deb9u2ubuntu0.1+esm1
uriparser_projecturiparser>= 0 < 0.9.3-2ubuntu0.1~esm30.9.3-2ubuntu0.1~esm3
uriparser_projecturiparser>= 0 < 0.9.6+dfsg-1ubuntu0.1~esm10.9.6+dfsg-1ubuntu0.1~esm1
uriparser_projecturiparser>= 0 < 0.9.7+dfsg-2ubuntu0.1~esm10.9.7+dfsg-2ubuntu0.1~esm1

CVSS provenance

nvdv3.18.6HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H
osv8.6HIGH
vendor_debian8.6HIGH
vendor_msrc8.6HIGH
vendor_redhat8.6HIGH
vendor_ubuntu8.6HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.