CVE-2024-57822
published 2025-01-10CVE-2024-57822: In Raptor RDF Syntax Library through 2.0.16, there is a heap-based buffer over-read when parsing triples with the nquads parser in…
PriorityP419medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.28%
20.7th percentile
In Raptor RDF Syntax Library through 2.0.16, there is a heap-based buffer over-read when parsing triples with the nquads parser in raptor_ntriples_parse_term_internal().
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | raptor2 | < raptor2 2.0.15-4+deb12u1 (bookworm) | raptor2 2.0.15-4+deb12u1 (bookworm) |
| librdf | raptor_rdf_syntax_library | <= 2.0.16 | — |
CVSS provenance
nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv6.5MEDIUM
vendor_ubuntu6.5MEDIUM
vendor_debian4.0MEDIUM
vendor_redhat4.0MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
raptor2 vulnerabilities
osv·2025-11-10·CVSS 6.5
CVE-2020-25713 [MEDIUM] raptor2 vulnerabilities
raptor2 vulnerabilities
Hanno Böck discovered that Raptor incorrectly handled memory operations
when processing certain input files. An attacker could possibly use this
issue to cause Raptor to crash, resulting in a denial of service.
(CVE-2020-25713)
Pedro Ribeiro discovered that Raptor incorrectly handled parsing certain
tuples. An attacker could possibly use this issue to cause Raptor to crash,
resulting in a denial of service. (CVE-2024-57822)
Pedro Ribeiro discovered that Raptor incorrectly handled parsing certain
turtles. An attacker could use this issue to cause Raptor to crash,
resulting in a denial of service, or possibly execute arbitrary code.
(CVE-2024-57823)
OSV
raptor2 vulnerabilities
osv·2025-03-03·CVSS 6.5
CVE-2020-25713 [MEDIUM] raptor2 vulnerabilities
raptor2 vulnerabilities
It was discovered that Raptor incorrectly handled memory operations when
processing certain input files. A remote attacker could possibly use this
issue to cause Raptor to crash, resulting in a denial of service. This
issue only affected Ubuntu 20.04 LTS and Ubuntu 22.04 LTS. (CVE-2020-25713)
It was discovered that Raptor incorrectly handled parsing certain tuples. A
remote attacker could possibly use this issue to cause Raptor to crash,
resulting in a denial of service. (CVE-2024-57822)
It was discovered that Raptor incorrectly handled parsing certain turtles.
A remote attacker could use this issue to cause Raptor to crash, resulting
in a denial of service, or possibly execute arbitrary code.
(CVE-2024-57823)
GHSA
GHSA-4g53-844p-p879: In Raptor RDF Syntax Library through 2
ghsa_unreviewed·2025-01-10
CVE-2024-57822 [MEDIUM] CWE-125 GHSA-4g53-844p-p879: In Raptor RDF Syntax Library through 2
In Raptor RDF Syntax Library through 2.0.16, there is a heap-based buffer over-read when parsing triples with the nquads parser in raptor_ntriples_parse_term_internal().
OSV
CVE-2024-57822: In Raptor RDF Syntax Library through 2
osv·2025-01-10·CVSS 5.5
CVE-2024-57822 [MEDIUM] CVE-2024-57822: In Raptor RDF Syntax Library through 2
In Raptor RDF Syntax Library through 2.0.16, there is a heap-based buffer over-read when parsing triples with the nquads parser in raptor_ntriples_parse_term_internal().
Ubuntu
Raptor vulnerabilities
vendor_ubuntu·2025-11-10·CVSS 6.5
CVE-2024-57822 [MEDIUM] Raptor vulnerabilities
Title: Raptor vulnerabilities
Summary: Several security issues were fixed in Raptor.
Hanno Böck discovered that Raptor incorrectly handled memory operations
when processing certain input files. An attacker could possibly use this
issue to cause Raptor to crash, resulting in a denial of service.
(CVE-2020-25713)
Pedro Ribeiro discovered that Raptor incorrectly handled parsing certain
tuples. An attacker could possibly use this issue to cause Raptor to crash,
resulting in a denial of service. (CVE-2024-57822)
Pedro Ribeiro discovered that Raptor incorrectly handled parsing certain
turtles. An attacker could use this issue to cause Raptor to crash,
resulting in a denial of service, or possibly execute arbitrary code.
(CVE-2024-57823)
Instructions: In general, a standard system update wil
Ubuntu
Raptor vulnerabilities
vendor_ubuntu·2025-03-03·CVSS 6.5
CVE-2024-57823 [MEDIUM] Raptor vulnerabilities
Title: Raptor vulnerabilities
Summary: Several security issues were fixed in Raptor.
It was discovered that Raptor incorrectly handled memory operations when
processing certain input files. A remote attacker could possibly use this
issue to cause Raptor to crash, resulting in a denial of service. This
issue only affected Ubuntu 20.04 LTS and Ubuntu 22.04 LTS. (CVE-2020-25713)
It was discovered that Raptor incorrectly handled parsing certain tuples. A
remote attacker could possibly use this issue to cause Raptor to crash,
resulting in a denial of service. (CVE-2024-57822)
It was discovered that Raptor incorrectly handled parsing certain turtles.
A remote attacker could use this issue to cause Raptor to crash, resulting
in a denial of service, or possibly execute arbitrary code.
(CVE-202
Red Hat
raptor: heap-based buffer over-read vulnerability
vendor_redhat·2025-01-10·CVSS 4.0
CVE-2024-57822 [MEDIUM] CWE-125 raptor: heap-based buffer over-read vulnerability
raptor: heap-based buffer over-read vulnerability
In Raptor RDF Syntax Library through 2.0.16, there is a heap-based buffer over-read when parsing triples with the nquads parser in raptor_ntriples_parse_term_internal().
A flaw was found in the Raptor RDF syntax library (librdf). A heap-based buffer over-read condition may be triggered when parsing specially crafted RDF triples via the nquads parser. This issue can lead to an application crash or other undefined behavior.
Package: raptor (Red Hat Enterprise Linux 6) - Out of support scope
Package: raptor2 (Red Hat Enterprise Linux 7) - Out of support scope
Package: raptor2 (Red Hat Enterprise Linux 8) - Out of support scope
Package: raptor2 (Red Hat Enterprise Linux 9) - Will not fix
Debian
CVE-2024-57822: raptor2 - In Raptor RDF Syntax Library through 2.0.16, there is a heap-based buffer over-r...
vendor_debian·2024·CVSS 4.0
CVE-2024-57822 [MEDIUM] CVE-2024-57822: raptor2 - In Raptor RDF Syntax Library through 2.0.16, there is a heap-based buffer over-r...
In Raptor RDF Syntax Library through 2.0.16, there is a heap-based buffer over-read when parsing triples with the nquads parser in raptor_ntriples_parse_term_internal().
Scope: local
bookworm: resolved (fixed in 2.0.15-4+deb12u1)
bullseye: resolved (fixed in 2.0.14-1.2+deb11u1)
forky: resolved (fixed in 2.0.16-6)
sid: resolved (fixed in 2.0.16-6)
trixie: resolved (fixed in 2.0.16-6)
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2025-01-10
Published