PT-2019-6339 · Pcre+7 · Pcre+7

·

CVE-2019-20454

·

Publicado

2019-07-28

·

Atualizado

2024-03-27

CVSS v2.0

7.8

Alta

VetorAV:N/AC:L/Au:N/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions PCRE versions prior to 10.34
Description An out-of-bounds read was discovered in PCRE when the pattern X is JIT compiled and used to match specially crafted subjects in non-UTF mode. This issue affects applications that use PCRE to parse untrusted input, allowing an attacker to crash the application. The flaw occurs in the do extuni no utf function in pcre2 jit compile.c.
Recommendations For versions prior to 10.34, update to version 10.34 or later to resolve the issue. As a temporary workaround, consider avoiding the use of the X pattern in JIT compiled regular expressions until a patch is available. Restrict access to untrusted input to minimize the risk of exploitation.

Exploit

Correção

Out of bounds Read

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

ALSA-2020:3662
ALSA-2020:4539
ALT-PU-2019-3185
ALT-PU-2022-1985
BDU:2023-02640
CESA-2020_3662
CESA-2020_4539
CVE-2019-20454
DLA-3363-1
MGASA-2020-0305
OPENSUSE-SU-2022:2649-1
OPENSUSE-SU-2022_2649-1
RHSA-2020:3662
RHSA-2020:4539
RHSA-2020_3662
RHSA-2020_4539
RLSA-2020:3662
RLSA-2020:4539
SUSE-SU-2022:2649-1
SUSE-SU-2022_2649-1

Produtos afetados

Alt Linux
Almalinux
Astra Linux
Centos
Pcre
Red Hat
Rocky Linux
Suse