CVE-2024-57823
raptor: integer underflow when normalizing a URI with the turtle parser
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
In Raptor RDF Syntax Library through 2.0.16, there is an integer underflow when normalizing a URI with the turtle parser in raptor_uri_normalize_path().
A flaw was found in the Raptor RDF syntax library (librdf). An integer underflow condition may be triggered when normalizing a URI with the turtle parser. This issue could cause memory corruption or an application crash, leading to a denial of service or other undefined behavior.
It was discovered that Raptor incorrectly handled memory operations when processing certain input files. A remote attacker could possibly use this issue to cause Raptor to crash, resulting in a denial of service. This issue only affected Ubuntu 20.04 LTS and Ubuntu 22.04 LTS. It was discovered that Raptor incorrectly handled parsing certain tuples. A remote attacker could possibly use this issue to cause Raptor to crash, resulting in a denial of service.
CVSS Scores
SSVC
- Decision:Attend
Timeline
- 2025-01-10 CVE Reserved
- 2025-01-10 CVE Published
- 2025-01-10 CVE Updated
- 2025-03-30 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-191: Integer Underflow (Wrap or Wraparound)
CAPEC
References (5)
URL | Tag | Source |
---|---|---|
https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1067896 | ||
https://github.com/dajobe/raptor/issues/70 | ||
https://github.com/pedrib/PoC/blob/master/fuzzing/raptor-fuzz.md |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
https://access.redhat.com/security/cve/CVE-2024-57823 | 2025-01-15 | |
https://bugzilla.redhat.com/show_bug.cgi?id=2336921 | 2025-01-15 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Librdf Search vendor "Librdf" | Raptor RDF Syntax Library Search vendor "Librdf" for product "Raptor RDF Syntax Library" | <= 2.0.16 Search vendor "Librdf" for product "Raptor RDF Syntax Library" and version " <= 2.0.16" | en |
Affected
|