Buffer Overflow Vulnerability in UriQuery
CVE-2024-34402

8.6HIGH

Key Information:

Vendor

uriparser

Status
Vendor
CVE Published:
3 May 2024

What is CVE-2024-34402?

An integer overflow vulnerability was discovered in the UriQueryEngine of uriparser versions up to and including 0.9.7. This flaw arises from improper handling of long keys or values, potentially resulting in a buffer overflow, which could allow for unauthorized access or manipulation of memory. This vulnerability necessitates immediate attention to prevent exploitation, particularly in applications relying on the affected version of uriparser.

References

CVSS V3.1

Score:
8.6
Severity:
HIGH
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.