CVE-2019-19012
17.11.2019, 18:15
An integer overflow in the search_in_range function in regexec.c in Oniguruma 6.x before 6.9.4_rc2 leads to an out-of-bounds read, in which the offset of this read is under the control of an attacker. (This only affects the 32-bit compiled version). Remote attackers can cause a denial-of-service or information disclosure, or possibly have unspecified other impact, via a crafted regular expression.Enginsight
Vendor | Product | Version |
---|---|---|
oniguruma_project | oniguruma | 6.0.0 ≤ 𝑥 ≤ 6.9.3 |
oniguruma_project | oniguruma | 6.9.4:rc1 |
debian | debian_linux | 8.0 |
redhat | enterprise_linux | 8.0 |
𝑥
= Vulnerable software versions

Debian Releases

Ubuntu Releases
Ubuntu Product | |||||||||||||||||||||||||
---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
libonig |
|
Common Weakness Enumeration
References