CVE-2024-34403 is an integer overflow vulnerability in uriparser versions through 0.9.7, specifically within the ComposeQueryMallocExMm function in UriQuery.c, affecting products like Fedora and uriparser_project. Rated as Medium severity (CVSS 5.9), it has a network attack vector and high attack complexity, potentially leading to a denial of service. There is currently no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant media coverage, though it has received some community discussion.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 0.9.7CPE matchmatch criteria | cpe:2.3:a:uriparser_project:uriparser:*:*:*:*:*:*:*:* | ||
38CPE matchmatch criteria | cpe:2.3:o:fedoraproject:fedora:38:*:*:*:*:*:*:* | ||
39CPE matchmatch criteria | cpe:2.3:o:fedoraproject:fedora:39:*:*:*:*:*:*:* | ||
40CPE matchmatch criteria | cpe:2.3:o:fedoraproject:fedora:40:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
An issue was discovered in uriparser through 0.9.7. ComposeQueryMallocExMm in UriQuery.c has an integer overflow via a long string.
May 14, 2024uriparser: integer overflow via a long string in ComposeQueryMallocExMm() in UriQuery.c
May 3, 2024