[Git][security-tracker-team/security-tracker][master] Add CVE-2025-67899/uriparser

Salvatore Bonaccorso (@carnil) carnil at debian.org
Mon Dec 15 08:34:30 GMT 2025



Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker


Commits:
f67bbd64 by Salvatore Bonaccorso at 2025-12-15T09:33:24+01:00
Add CVE-2025-67899/uriparser

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -7,7 +7,9 @@ CVE-2025-67901 (openrsync through 0.5.0, as used in OpenBSD through 7.8 and on o
 CVE-2025-67900 (NXLog Agent before 6.11 can load a file specified by the OPENSSL_CONF  ...)
 	TODO: check
 CVE-2025-67899 (uriparser through 0.9.9 allows unbounded recursion and stack consumpti ...)
-	TODO: check
+	- uriparser <unfixed>
+	NOTE: https://github.com/uriparser/uriparser/issues/282
+	NOTE: https://github.com/uriparser/uriparser/pull/284
 CVE-2025-67898 (MJML through 4.18.0 allows mj-include directory traversal to test file ...)
 	TODO: check
 CVE-2025-14712 (Student Learning Assessment and Support System developed by JHENG GAO  ...)



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/f67bbd648168b1ed78b9a6c356205a3078c71132

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/f67bbd648168b1ed78b9a6c356205a3078c71132
You're receiving this email because of your account on salsa.debian.org.


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20251215/fd2becdb/attachment.htm>


More information about the debian-security-tracker-commits mailing list