CVE-2019-20838

libpcre in PCRE before 8.43 allows a subject buffer over-read in JIT when UTF is disabled, and \X or \R has more than one fixed quantifier, a related issue to CVE-2019-20454.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
7.5 HIGH
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
mitreCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 43%
VendorProductVersion
pcrepcre
𝑥
< 8.43
applemacos
𝑥
< 11.0.1
splunkuniversal_forwarder
8.2.0 ≤
𝑥
< 8.2.12
splunkuniversal_forwarder
9.0.0 ≤
𝑥
< 9.0.6
splunkuniversal_forwarder
9.1.0
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
pcre3
bullseye
unimportant
bookworm
unimportant
sid
unimportant
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
pcre3
noble
needed
mantic
ignored
lunar
ignored
kinetic
ignored
jammy
Fixed 2:8.39-13ubuntu0.22.04.1
released
impish
Fixed 2:8.39-13ubuntu0.21.10.1
released
hirsute
ignored
groovy
ignored
focal
Fixed 2:8.39-12ubuntu0.1
released
eoan
ignored
bionic
Fixed 2:8.39-9ubuntu0.1
released
xenial
not-affected
trusty
not-affected