|
Message-ID: <20240506103221.GA8492@openwall.com> Date: Mon, 6 May 2024 12:32:22 +0200 From: Solar Designer <solar@...nwall.com> To: oss-security@...ts.openwall.com Subject: Re: Fwd: uriparser 0.9.8 released, includes security fixes Hi, On Mon, May 06, 2024 at 12:06:18PM +0200, Sebastian Pipping wrote: > Ealier today uriparser 0.9.8 has been released. Version 0.9.8 fixes two > security issues: CVE-2024-34402 and CVE-2024-34403. For more > details, please check out the change log [1]. > > If you happen to have patches for uriparser that are still required with > 0.9.8, please send them my way. > [1] https://github.com/uriparser/uriparser/blob/uriparser-0.9.8/ChangeLog Let's be including vulnerability information right in here, not only via reference, so: * Fixed: [CVE-2024-34402] Protect against integer overflow in ComposeQueryEngine (GitHub #183, GitHub #185) * Fixed: [CVE-2024-34403] Protect against integer overflow in ComposeQueryMallocExMm (GitHub #183, GitHub #186) Thanks, Alexander
Powered by blists - more mailing lists
Please check out the Open Source Software Security Wiki, which is counterpart to this mailing list.
Confused about mailing lists and their use? Read about mailing lists on Wikipedia and check out these guidelines on proper formatting of your messages.