All errata/c9f2/ALT-PU-2025-12933-2
ALT-PU-2025-12933-2

Package update raptor2 in branch c9f2

Version2.0.16-alt2
Published2025-10-14
Max severityCRITICAL
Severity:

Closed issues (4)

BDU:2025-03460
CRITICAL9.3

Уязвимость функции raptor_uri_normalize_path() библиотеки Raptor, позволяющая нарушителю получить выполнить произвольный код

Published: 2025-03-27Modified: 2026-03-04
CVSS 3.xCRITICAL 9.3
CVSS:3.x/AV:L/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
CVSS 2.0HIGH 7.2
CVSS:2.0/AV:L/AC:L/Au:N/C:C/I:C/A:C
References
BDU:2025-11887
MEDIUM4.0

Уязвимость функции raptor_ntriples_parse_term_internal() библиотеки RAPtor, позволяющая нарушителю вызвать отказ в обслуживании

Published: 2025-09-28Modified: 2026-03-04
CVSS 3.xMEDIUM 4.0
CVSS:3.x/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
CVSS 2.0LOW 2.1
CVSS:2.0/AV:L/AC:L/Au:N/C:N/I:N/A:P
References
CVE-2024-57822
MEDIUM5.5

In Raptor RDF Syntax Library through 2.0.16, there is a heap-based buffer over-read when parsing triples with the nquads parser in raptor_ntriples_parse_term_internal().

Published: 2025-01-10Modified: 2025-11-03
CVSS 3.xMEDIUM 5.5
CVSS:3.x/CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
CVE-2024-57823
MEDIUM5.5

In Raptor RDF Syntax Library through 2.0.16, there is an integer underflow when normalizing a URI with the turtle parser in raptor_uri_normalize_path().

Published: 2025-01-10Modified: 2025-11-03
CVSS 3.xMEDIUM 5.5
CVSS:3.x/CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H