CVE-2024-57823

NameCVE-2024-57823
DescriptionIn Raptor RDF Syntax Library through 2.0.16, there is an integer underflow when normalizing a URI with the turtle parser in raptor_uri_normalize_path().
SourceCVE (at NVD; CERT, LWN, oss-sec, fulldisc, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)
Debian Bugs1067896

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
raptor2 (PTS)bullseye2.0.14-1.2vulnerable
bookworm2.0.15-4vulnerable
sid, trixie2.0.16-4vulnerable

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
raptor2source(unstable)(unfixed)1067896

Notes

[bookworm] - raptor2 <postponed> (Minor issue, revisit when fixed upstream)
[bullseye] - raptor2 <postponed> (Minor issue, revisit when fixed upstream)
https://github.com/pedrib/PoC/blob/master/fuzzing/raptor-fuzz.md
https://github.com/dajobe/raptor/issues/70

Search for package or bug name: Reporting problems