An issue was discovered in uriparser before 0.9.0. UriQuery.c allows an integer overflow via a uriComposeQuery* or uriComposeQueryEx* function because of an unchecked multiplication.
{ "binaries": [ { "binary_version": "0.8.4-1+deb9u2build0.18.04.1", "binary_name": "liburiparser-dev" }, { "binary_version": "0.8.4-1+deb9u2build0.18.04.1", "binary_name": "liburiparser-doc" }, { "binary_version": "0.8.4-1+deb9u2build0.18.04.1", "binary_name": "liburiparser1" }, { "binary_version": "0.8.4-1+deb9u2build0.18.04.1", "binary_name": "liburiparser1-dbgsym" } ], "availability": "No subscription required" }
{ "binaries": [ { "binary_version": "0.9.3-2", "binary_name": "liburiparser-dev" }, { "binary_version": "0.9.3-2", "binary_name": "liburiparser-doc" }, { "binary_version": "0.9.3-2", "binary_name": "liburiparser1" }, { "binary_version": "0.9.3-2", "binary_name": "liburiparser1-dbgsym" } ], "availability": "No subscription required" }