From 89d1dcc96d3f16d8b9767bfdd25e1c7a8ae64486 Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?Adrian=20Schr=C3=B6ter?= Date: Thu, 28 Nov 2024 14:31:16 +0100 Subject: [PATCH] Adding patchinfo patchinfo.20240925225150241819.88530327813663 --- .../_patchinfo | 20 +++++++++++++++++++ 1 file changed, 20 insertions(+) create mode 100644 patchinfo.20240925225150241819.88530327813663/_patchinfo diff --git a/patchinfo.20240925225150241819.88530327813663/_patchinfo b/patchinfo.20240925225150241819.88530327813663/_patchinfo new file mode 100644 index 0000000..699d5bd --- /dev/null +++ b/patchinfo.20240925225150241819.88530327813663/_patchinfo @@ -0,0 +1,20 @@ + + + VUL-0: CVE-2024-34402: uriparser: integer overflow via long keys or values in ComposeQueryEngine() in UriQuery.c + VUL-0: CVE-2024-34403: uriparser: integer overflow via a long string in ComposeQueryMallocExMm() in UriQuery.c + + + adamm + important + security + Security update for uriparser + This update for uriparser fixes the following issues: + +- Protect against integer overflow in ComposeQueryEngine (bsc#1223887, CVE-2024-34402) +- Protect against integer overflow in ComposeQueryMallocExMm (bsc#1223888, CVE-2024-34403) +- enable unit tests + + + uriparser + +