Amazon Linux 2 Security Advisory: ALAS-2019-1356
Advisory Release Date: 2019-11-04 22:39 Pacific
Advisory Updated Date: 2019-11-07 00:32 Pacific
An issue was discovered in uriparser before 0.9.0. UriQuery.c allows an out-of-bounds write via a uriComposeQuery* or uriComposeQueryEx* function because the '&' character is mishandled in certain contexts.(CVE-2018-19198)
An issue was discovered in uriparser before 0.9.0. UriQuery.c allows an integer overflow via a uriComposeQuery* or uriComposeQueryEx* function because of an unchecked multiplication.(CVE-2018-19199)
Affected Packages:
uriparser
Note:
This advisory is applicable to Amazon Linux 2 (AL2) Core repository. Visit this FAQ section for the difference between AL2 Core and AL2 Extras advisories.
Issue Correction:
Run yum update uriparser to update your system.
aarch64:
uriparser-0.7.5-10.amzn2.aarch64
uriparser-devel-0.7.5-10.amzn2.aarch64
uriparser-debuginfo-0.7.5-10.amzn2.aarch64
i686:
uriparser-0.7.5-10.amzn2.i686
uriparser-devel-0.7.5-10.amzn2.i686
uriparser-debuginfo-0.7.5-10.amzn2.i686
src:
uriparser-0.7.5-10.amzn2.src
x86_64:
uriparser-0.7.5-10.amzn2.x86_64
uriparser-devel-0.7.5-10.amzn2.x86_64
uriparser-debuginfo-0.7.5-10.amzn2.x86_64