ALAS2-2019-1356


Amazon Linux 2 Security Advisory: ALAS-2019-1356
Advisory Release Date: 2019-11-04 22:39 Pacific
Advisory Updated Date: 2019-11-07 00:32 Pacific
Severity: Medium

Issue Overview:

An issue was discovered in uriparser before 0.9.0. UriQuery.c allows an out-of-bounds write via a uriComposeQuery* or uriComposeQueryEx* function because the '&' character is mishandled in certain contexts.(CVE-2018-19198)

An issue was discovered in uriparser before 0.9.0. UriQuery.c allows an integer overflow via a uriComposeQuery* or uriComposeQueryEx* function because of an unchecked multiplication.(CVE-2018-19199)


Affected Packages:

uriparser


Note:

This advisory is applicable to Amazon Linux 2 (AL2) Core repository. Visit this FAQ section for the difference between AL2 Core and AL2 Extras advisories.


Issue Correction:
Run yum update uriparser to update your system.

New Packages:
aarch64:
    uriparser-0.7.5-10.amzn2.aarch64
    uriparser-devel-0.7.5-10.amzn2.aarch64
    uriparser-debuginfo-0.7.5-10.amzn2.aarch64

i686:
    uriparser-0.7.5-10.amzn2.i686
    uriparser-devel-0.7.5-10.amzn2.i686
    uriparser-debuginfo-0.7.5-10.amzn2.i686

src:
    uriparser-0.7.5-10.amzn2.src

x86_64:
    uriparser-0.7.5-10.amzn2.x86_64
    uriparser-devel-0.7.5-10.amzn2.x86_64
    uriparser-debuginfo-0.7.5-10.amzn2.x86_64