CVE-2024-57823
published 2025-01-10CVE-2024-57823: In Raptor RDF Syntax Library through 2.0.16, there is an integer underflow when normalizing a URI with the turtle parser in raptor_uri_normalize_path().
PriorityP419medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.32%
24.0th percentile
In Raptor RDF Syntax Library through 2.0.16, there is an integer underflow when normalizing a URI with the turtle parser in raptor_uri_normalize_path().
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | raptor2 | < raptor2 2.0.15-4+deb12u1 (bookworm) | raptor2 2.0.15-4+deb12u1 (bookworm) |
| librdf | raptor_rdf_syntax_library | <= 2.0.16 | — |
CVSS provenance
nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv6.5MEDIUM
vendor_debian9.3CRITICAL
vendor_redhat9.3CRITICAL
vendor_ubuntu6.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
raptor2 vulnerabilities
osv·2025-11-10·CVSS 6.5
CVE-2020-25713 [MEDIUM] raptor2 vulnerabilities
raptor2 vulnerabilities
Hanno Böck discovered that Raptor incorrectly handled memory operations
when processing certain input files. An attacker could possibly use this
issue to cause Raptor to crash, resulting in a denial of service.
(CVE-2020-25713)
Pedro Ribeiro discovered that Raptor incorrectly handled parsing certain
tuples. An attacker could possibly use this issue to cause Raptor to crash,
resulting in a denial of service. (CVE-2024-57822)
Pedro Ribeiro discovered that Raptor incorrectly handled parsing certain
turtles. An attacker could use this issue to cause Raptor to crash,
resulting in a denial of service, or possibly execute arbitrary code.
(CVE-2024-57823)
OSV
raptor2 vulnerabilities
osv·2025-03-03·CVSS 6.5
CVE-2020-25713 [MEDIUM] raptor2 vulnerabilities
raptor2 vulnerabilities
It was discovered that Raptor incorrectly handled memory operations when
processing certain input files. A remote attacker could possibly use this
issue to cause Raptor to crash, resulting in a denial of service. This
issue only affected Ubuntu 20.04 LTS and Ubuntu 22.04 LTS. (CVE-2020-25713)
It was discovered that Raptor incorrectly handled parsing certain tuples. A
remote attacker could possibly use this issue to cause Raptor to crash,
resulting in a denial of service. (CVE-2024-57822)
It was discovered that Raptor incorrectly handled parsing certain turtles.
A remote attacker could use this issue to cause Raptor to crash, resulting
in a denial of service, or possibly execute arbitrary code.
(CVE-2024-57823)
OSV
CVE-2024-57823: In Raptor RDF Syntax Library through 2
osv·2025-01-10·CVSS 5.5
CVE-2024-57823 [MEDIUM] CVE-2024-57823: In Raptor RDF Syntax Library through 2
In Raptor RDF Syntax Library through 2.0.16, there is an integer underflow when normalizing a URI with the turtle parser in raptor_uri_normalize_path().
GHSA
GHSA-4mjp-wj5r-mc96: In Raptor RDF Syntax Library through 2
ghsa_unreviewed·2025-01-10
CVE-2024-57823 [CRITICAL] CWE-191 GHSA-4mjp-wj5r-mc96: In Raptor RDF Syntax Library through 2
In Raptor RDF Syntax Library through 2.0.16, there is an integer underflow when normalizing a URI with the turtle parser in raptor_uri_normalize_path().
Ubuntu
Raptor vulnerabilities
vendor_ubuntu·2025-11-10·CVSS 6.5
CVE-2024-57822 [MEDIUM] Raptor vulnerabilities
Title: Raptor vulnerabilities
Summary: Several security issues were fixed in Raptor.
Hanno Böck discovered that Raptor incorrectly handled memory operations
when processing certain input files. An attacker could possibly use this
issue to cause Raptor to crash, resulting in a denial of service.
(CVE-2020-25713)
Pedro Ribeiro discovered that Raptor incorrectly handled parsing certain
tuples. An attacker could possibly use this issue to cause Raptor to crash,
resulting in a denial of service. (CVE-2024-57822)
Pedro Ribeiro discovered that Raptor incorrectly handled parsing certain
turtles. An attacker could use this issue to cause Raptor to crash,
resulting in a denial of service, or possibly execute arbitrary code.
(CVE-2024-57823)
Instructions: In general, a standard system update wil
Ubuntu
Raptor vulnerabilities
vendor_ubuntu·2025-03-03·CVSS 6.5
CVE-2024-57823 [MEDIUM] Raptor vulnerabilities
Title: Raptor vulnerabilities
Summary: Several security issues were fixed in Raptor.
It was discovered that Raptor incorrectly handled memory operations when
processing certain input files. A remote attacker could possibly use this
issue to cause Raptor to crash, resulting in a denial of service. This
issue only affected Ubuntu 20.04 LTS and Ubuntu 22.04 LTS. (CVE-2020-25713)
It was discovered that Raptor incorrectly handled parsing certain tuples. A
remote attacker could possibly use this issue to cause Raptor to crash,
resulting in a denial of service. (CVE-2024-57822)
It was discovered that Raptor incorrectly handled parsing certain turtles.
A remote attacker could use this issue to cause Raptor to crash, resulting
in a denial of service, or possibly execute arbitrary code.
(CVE-202
Red Hat
raptor: integer underflow when normalizing a URI with the turtle parser
vendor_redhat·2025-01-10·CVSS 9.3
CVE-2024-57823 [CRITICAL] CWE-191 raptor: integer underflow when normalizing a URI with the turtle parser
raptor: integer underflow when normalizing a URI with the turtle parser
In Raptor RDF Syntax Library through 2.0.16, there is an integer underflow when normalizing a URI with the turtle parser in raptor_uri_normalize_path().
A flaw was found in the Raptor RDF syntax library (librdf). An integer underflow condition may be triggered when normalizing a URI with the turtle parser. This issue could cause memory corruption or an application crash, leading to a denial of service or other undefined behavior.
Statement: This vulnerability in the Raptor RDF syntax library (librdf) ios marked as
important severity rather than moderate due to the potential for memory corruption resulting from the integer underflow condition. Memory corruption can lead to application crashes, creating a reliable vec
Debian
CVE-2024-57823: raptor2 - In Raptor RDF Syntax Library through 2.0.16, there is an integer underflow when ...
vendor_debian·2024·CVSS 9.3
CVE-2024-57823 [CRITICAL] CVE-2024-57823: raptor2 - In Raptor RDF Syntax Library through 2.0.16, there is an integer underflow when ...
In Raptor RDF Syntax Library through 2.0.16, there is an integer underflow when normalizing a URI with the turtle parser in raptor_uri_normalize_path().
Scope: local
bookworm: resolved (fixed in 2.0.15-4+deb12u1)
bullseye: resolved (fixed in 2.0.14-1.2+deb11u1)
forky: resolved (fixed in 2.0.16-6)
sid: resolved (fixed in 2.0.16-6)
trixie: resolved (fixed in 2.0.16-6)
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2025-01-10
Published