Debian DLA-1581-1 : uriparser security update
High Nessus Plugin ID 119053
SynopsisThe remote Debian host is missing a security update.
DescriptionMultiple vulnerabilities have been discovered in uriparser, an Uniform Resource Identifiers (URIs) parsing library.
UriQuery.c allows an out-of-bounds write via a uriComposeQuery* or uriComposeQueryEx* function because the '&' character is mishandled in certain contexts.
UriQuery.c allows an integer overflow via a uriComposeQuery* or uriComposeQueryEx* function because of an unchecked multiplication.
UriCommon.c allows attempted operations on NULL input via a uriResetUri* function.
For Debian 8 'Jessie', these problems have been fixed in version 0.8.0.1-2+deb8u1.
We recommend that you upgrade your uriparser packages.
NOTE: Tenable Network Security has extracted the preceding description block directly from the DLA security advisory. Tenable has attempted to automatically clean and format it as much as possible without introducing additional issues.
SolutionUpgrade the affected liburiparser-dev, and liburiparser1 packages.