UbuntuUpdates.org

Package "libraptor2-dev"

Name: libraptor2-dev

Description:

Raptor 2 RDF syntax library development libraries and headers

Latest version: 2.0.15-0ubuntu4.1
Release: jammy (22.04)
Level: updates
Repository: main
Head package: raptor2
Homepage: http://librdf.org/raptor/

Links


Download "libraptor2-dev"


Other versions of "libraptor2-dev" in Jammy

Repository Area Version
base main 2.0.15-0ubuntu4
security main 2.0.15-0ubuntu4.1

Changelog

Version: 2.0.15-0ubuntu4.1 2025-03-03 21:07:00 UTC

  raptor2 (2.0.15-0ubuntu4.1) jammy-security; urgency=medium

  * SECURITY UPDATE: out of bounds array access
    - debian/patches/CVE-2020-25713.patch: compare namespace declarations
      correctly in src/raptor_xml_writer.c.
    - CVE-2020-25713
  * SECURITY UPDATE: heap overread when parsing triples
    - debian/patches/CVE-2024-57822.patch: only allow looking at the last
      character of a bnode ID only if bnode length >0 in
      src/raptor_ntriples.c.
    - debian/patches/CVE-2024-5782x-tests.patch: added test in
      configure.ac, tests/Makefile.am, tests/bugs/Makefile.am,
      tests/bugs/issue70b.c.
    - CVE-2024-57822
  * SECURITY UPDATE: integer overflow when normalizing a URI
    - debian/patches/CVE-2024-57823.patch: return empty buffer if path gets
      to 0 length in src/raptor_rfc2396.c.
    - debian/patches/CVE-2024-5782x-tests.patch: added test in
      configure.ac, tests/Makefile.am, tests/bugs/Makefile.am,
      tests/bugs/issue70a.c.
    - CVE-2024-57823

 -- Marc Deslauriers <email address hidden> Tue, 25 Feb 2025 08:37:54 -0500

CVE-2020-25713 A malformed input file can lead to a segfault due to an out of bounds array access in raptor_xml_writer_start_element_common.
CVE-2024-57822 In Raptor RDF Syntax Library through 2.0.16, there is a heap-based buffer over-read when parsing triples with the nquads parser in raptor_ntriples_pa
CVE-2024-57823 In Raptor RDF Syntax Library through 2.0.16, there is an integer underflow when normalizing a URI with the turtle parser in raptor_uri_normalize_path



About   -   Send Feedback to @ubuntu_updates