7.5
CVSSv2

CVE-2018-19199

Published: 12/11/2018 Updated: 06/08/2019
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
CVSS v3 Base Score: 9.8 | Impact Score: 5.9 | Exploitability Score: 3.9
VMScore: 668
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

An issue exists in uriparser prior to 0.9.0. UriQuery.c allows an integer overflow via a uriComposeQuery* or uriComposeQueryEx* function because of an unchecked multiplication.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

uriparser project uriparser

debian debian linux 8.0

Vendor Advisories

Synopsis Moderate: uriparser security update Type/Severity Security Advisory: Moderate Topic An update for uriparser is now available for Red Hat Enterprise Linux 7Red Hat Product Security has rated this update as having a security impact of Moderate A Common Vulnerability Scoring System (CVSS) base score ...
Debian Bug report logs - #913817 uriparser: CVE-2018-19198 CVE-2018-19199 CVE-2018-19200 Package: src:uriparser; Maintainer for src:uriparser is Jörg Frings-Fürst <debian@jffemail>; Reported by: Salvatore Bonaccorso <carnil@debianorg> Date: Thu, 15 Nov 2018 15:54:02 UTC Severity: important Tags: security, upstrea ...
An issue was discovered in uriparser before 090 UriQueryc allows an out-of-bounds write via a uriComposeQuery* or uriComposeQueryEx* function because the '&' character is mishandled in certain contexts(CVE-2018-19198) An issue was discovered in uriparser before 090 UriQueryc allows an integer overflow via a uriComposeQuery* or uriCompo ...