4.3
CVSSv2

CVE-2021-46142

Published: 06/01/2022 Updated: 07/11/2023
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
CVSS v3 Base Score: 5.5 | Impact Score: 3.6 | Exploitability Score: 1.8
VMScore: 383
Vector: AV:N/AC:M/Au:N/C:N/I:N/A:P

Vulnerability Summary

An issue exists in uriparser prior to 0.9.6. It performs invalid free operations in uriNormalizeSyntax.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

uriparser project uriparser

fedoraproject fedora 34

fedoraproject extra packages for enterprise linux 8.0

fedoraproject fedora 35

debian debian linux 9.0

debian debian linux 10.0

debian debian linux 11.0

opensuse backports sle-15

opensuse factory -

opensuse leap 15.3

Vendor Advisories

uriparser could be made to crash if it received specially crafted input ...
Two vulnerabilities were discovered in uriparser, a library that parses Uniform Resource Identifiers (URIs), which may result in denial of service or potentially in the the execution of arbitrary code For the oldstable distribution (buster), these problems have been fixed in version 091-1+deb10u1 For the stable distribution (bullseye), these pr ...
An issue was discovered in uriparser before 096 It performs invalid free operations in uriNormalizeSyntax (CVE-2021-46142) ...
An issue was discovered in uriparser before 096 It performs invalid free operations in uriNormalizeSyntax ...
invalid free operations in uriNormalizeSyntax ...