PT-2019-5896 · Oniguruma+7 · Oniguruma+7

Rkx1209

·

Published

2019-07-28

·

Updated

2024-02-20

·

CVE-2019-16163

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Oniguruma versions prior to 6.9.3
Description The issue is related to uncontrolled recursion in the Oniguruma library for regular expressions. This can lead to a stack exhaustion, potentially allowing a remote attacker to cause a denial of service.
Recommendations For versions prior to 6.9.3, update to version 6.9.3 or later to resolve the issue. As a temporary workaround, consider restricting the use of recursive functions in regparse.c to minimize the risk of exploitation.

Exploit

Fix

Uncontrolled Recursion

Weakness Enumeration

Related Identifiers

ALSA-2020:3662
ALSA-2024:0889
ALT-PU-2019-2455
ALT-PU-2019-3215
BDU:2021-03616
CESA-2020_3662
CESA-2024_0889
CVE-2019-16163
DLA-1918-1
DLA-2431-1
MGASA-2020-0029
OPENSUSE-SU-2022_3327-1
RHSA-2020:3662
RHSA-2020_3662
RHSA-2024:0409
RHSA-2024:0572
RHSA-2024:0889
RHSA-2024_0889
RLSA-2020:3662
SUSE-SU-2022:3327-1
USN-4460-1
USN-5662-1

Affected Products

Alt Linux
Almalinux
Centos
Oniguruma
Red Hat
Rocky Linux
Suse
Ubuntu