CVE-2024-57822

NameCVE-2024-57822
DescriptionIn Raptor RDF Syntax Library through 2.0.16, there is a heap-based buffer over-read when parsing triples with the nquads parser in raptor_ntriples_parse_term_internal().
SourceCVE (at NVD; CERT, LWN, oss-sec, fulldisc, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)
Debian Bugs1067896

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
raptor2 (PTS)bullseye2.0.14-1.2vulnerable
bookworm2.0.15-4vulnerable
sid, trixie2.0.16-4vulnerable

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
raptor2source(unstable)(unfixed)1067896

Notes

[bookworm] - raptor2 <postponed> (Minor issue, revisit when fixed upstream)
[bullseye] - raptor2 <postponed> (Minor issue, revisit when fixed upstream)
https://github.com/pedrib/PoC/blob/master/fuzzing/raptor-fuzz.md
https://github.com/dajobe/raptor/issues/70

Search for package or bug name: Reporting problems