PT-2019-5888 · Oniguruma+8 · Oniguruma+8

Nikic

·

Published

2019-11-25

·

Updated

2024-06-15

·

CVE-2019-19246

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Oniguruma versions prior to 6.9.4
Description The issue is related to a heap-based buffer over-read in the str lower case match function within the Oniguruma library, which is used for regular expression processing. This can potentially allow a remote attacker to cause a denial of service.
Recommendations For Oniguruma versions prior to 6.9.4, update to version 6.9.4 or later to resolve the issue. As a temporary workaround, consider restricting the use of the str lower case match function in the Oniguruma library until a patch is available.

Exploit

Fix

Out of bounds Read

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALSA-2020:3662
ALT-PU-2019-3211
ALT-PU-2019-3215
BDU:2021-03595
CESA-2020_3662
CVE-2019-19246
DLA-2020-1
DLA-2431-1
MGASA-2020-0029
OPENSUSE-SU-2022_3327-1
OPENSUSE-SU-2024:11111-1
RHSA-2020:3662
RHSA-2020:5275
RHSA-2020_3662
RLSA-2020:3662
SUSE-SU-2022:3327-1
USN-4460-1
USN-5662-1

Affected Products

Alt Linux
Almalinux
Astra Linux
Centos
Oniguruma
Red Hat
Rocky Linux
Suse
Ubuntu