PT-2019-5904 · Oniguruma+8 · Oniguruma+8

Manhnd

·

Published

2019-11-06

·

Updated

2025-09-29

·

CVE-2019-19203

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Oniguruma versions prior to 6.9.4 rc2
Description The issue is related to a heap-based buffer over-read in the gb18030 mbc enc len function, located in the gb18030.c file. This occurs because a UChar pointer is dereferenced without checking if it has passed the end of the matched string. The vulnerability can be exploited by a remote attacker to cause a denial of service.
Recommendations For Oniguruma versions prior to 6.9.4 rc2, update to version 6.9.4 rc2 or later to resolve the issue. As a temporary workaround, consider restricting the use of the gb18030 mbc enc len function until a patch is available.

Exploit

Fix

Out of bounds Read

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALSA-2020:3662
ALSA-2020_3662
ALSA-2020_4539
ALSA-2024:0889
ALSA-2025_16880
ALT-PU-2019-3211
ALT-PU-2019-3215
BDU:2021-03777
CESA-2020_3662
CESA-2024_0889
CVE-2019-19203
DLA-2431-1
ELSA-2020-3662
ELSA-2024-0889
MGASA-2020-0029
OPENSUSE-SU-2022_3327-1
OPENSUSE-SU-2024:11111-1
RHSA-2020:3662
RHSA-2020:5275
RHSA-2020_3662
RHSA-2024:0409
RHSA-2024:0572
RHSA-2024:0889
RHSA-2024_0889
RLSA-2020:3662
RLSA-2020_3662
SUSE-SU-2022:3327-1
SUSE-SU-2022_3327-1
USN-5662-1

Affected Products

Alt Linux
Almalinux
Astra Linux
Centos
Oniguruma
Red Hat
Rocky Linux
Suse
Ubuntu