PT-2020-10802 · Philip Hazel+10 · Pcre+10

Published

2019-02-24

·

Updated

2024-03-27

·

CVE-2019-20838

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions PCRE versions prior to 8.43
Description The issue allows a subject buffer over-read in JIT when UTF is disabled, and X or R has more than one fixed quantifier.
Recommendations For versions prior to 8.43, update to version 8.44 or later to resolve the issue.

Fix

Out of bounds Read

Weakness Enumeration

Related Identifiers

ALSA-2021:4373
ALT-PU-2019-1301
CESA-2021_4373
CVE-2019-20838
OPENSUSE-SU-2021:1441-1
OPENSUSE-SU-2021:3529-1
OPENSUSE-SU-2021_1441-1
OPENSUSE-SU-2021_3529-1
RHSA-2021:4373
RHSA-2021:4614
RHSA-2021_4373
RLSA-2021:4373
SUSE-SU-2021:3529-1
SUSE-SU-2021:3652-1
SUSE-SU-2021_3529-1
USN-5425-1

Affected Products

Alt Linux
Almalinux
Centos
Debian
Linuxmint
Apple Macos
Pcre
Red Hat
Rocky Linux
Suse
Ubuntu