CVE-2019-19246
25.11.2019, 17:15
Oniguruma through 6.9.3, as used in PHP 7.3.x and other products, has a heap-based buffer over-read in str_lower_case_match in regexec.c.Enginsight
| Vendor | Product | Version |
|---|---|---|
| oniguruma_project | oniguruma | 𝑥 ≤ 6.9.3 |
| php | php | 7.3.0 ≤ 𝑥 < 7.3.10 |
| canonical | ubuntu_linux | 14.04 |
| debian | debian_linux | 8.0 |
𝑥
= Vulnerable software versions
Debian Releases
Ubuntu Releases
Ubuntu Product | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| libonig |
|
Common Weakness Enumeration
References