PT-2019-5888 · Oniguruma+8 · Oniguruma+8

Nikic

·

Publicado

2019-11-25

·

Atualizado

2024-06-15

·

CVE-2019-19246

CVSS v3.1

7.5

Alta

VetorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Oniguruma versions prior to 6.9.4
Description The issue is related to a heap-based buffer over-read in the str lower case match function within the Oniguruma library, which is used for regular expression processing. This can potentially allow a remote attacker to cause a denial of service.
Recommendations For Oniguruma versions prior to 6.9.4, update to version 6.9.4 or later to resolve the issue. As a temporary workaround, consider restricting the use of the str lower case match function in the Oniguruma library until a patch is available.

Exploit

Correção

Out of bounds Read

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

ALSA-2020:3662
ALT-PU-2019-3211
ALT-PU-2019-3215
BDU:2021-03595
CESA-2020_3662
CVE-2019-19246
DLA-2020-1
DLA-2431-1
MGASA-2020-0029
OPENSUSE-SU-2022_3327-1
OPENSUSE-SU-2024:11111-1
RHSA-2020:3662
RHSA-2020:5275
RHSA-2020_3662
RLSA-2020:3662
SUSE-SU-2022:3327-1
USN-4460-1
USN-5662-1

Produtos afetados

Alt Linux
Almalinux
Astra Linux
Centos
Oniguruma
Red Hat
Rocky Linux
Suse
Ubuntu