Invalid Free Operations in uriparser Affecting Multiple Versions
CVE-2021-46142

5.5MEDIUM

Key Information:

Status
Vendor
CVE Published:
6 January 2022

What is CVE-2021-46142?

An issue was discovered in uriparser versions prior to 0.9.6, where invalid free operations were triggered in the uriNormalizeSyntax function. This vulnerability can potentially lead to unexpected behavior or crashes, compromising the integrity and reliability of applications relying on this library for URI parsing.

References

CVSS V3.1

Score:
5.5
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.