CVE-2024-57823Integer Underflow (Wrap or Wraparound) in Raptor RDF Syntax Library

Severity
5.5MEDIUMNVD
OSV6.5
EPSS
0.0%
top 88.05%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJan 10
Latest updateNov 10

Description

In Raptor RDF Syntax Library through 2.0.16, there is an integer underflow when normalizing a URI with the turtle parser in raptor_uri_normalize_path().

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:HExploitability: 1.8 | Impact: 3.6

Affected Packages2 packages

debiandebian/raptor2< raptor2 2.0.15-4+deb12u1 (bookworm)

🔴Vulnerability Details

4
OSV
raptor2 vulnerabilities2025-11-10
OSV
raptor2 vulnerabilities2025-03-03
OSV
CVE-2024-57823: In Raptor RDF Syntax Library through 22025-01-10
GHSA
GHSA-4mjp-wj5r-mc96: In Raptor RDF Syntax Library through 22025-01-10

📋Vendor Advisories

4
Ubuntu
Raptor vulnerabilities2025-11-10
Ubuntu
Raptor vulnerabilities2025-03-03
Red Hat
raptor: integer underflow when normalizing a URI with the turtle parser2025-01-10
Debian
CVE-2024-57823: raptor2 - In Raptor RDF Syntax Library through 2.0.16, there is an integer underflow when ...2024
CVE-2024-57823 — Integer Underflow (Wrap or Wraparound) | cvebase