[Forgot Password]
Login  Register Subscribe

30479

 
 

423868

 
 

250770

 
 

909

 
 

196157

 
 

282

Paid content will be excluded from the download.


Download | Alert*
OVAL

Oniguruma: Multiple vulnerabilities CVE-2019-19012, CVE-2019-19203, CVE-2019-19204, CVE-2019-19246)

ID: oval:org.secpod.oval:def:1801662Date: (C)2020-01-14   (M)2023-11-10
Class: PATCHFamily: unix




Oniguruma through 6.9.3, as used in PHP 7.3.x and other products, has a heap-based buffer over-read in str_lower_case_match in regexec.c.An issue was discovered in Oniguruma 6.x before 6.9.4_rc2. In the function gb18030_mbc_enc_len in file gb18030.c, a UChar pointer is dereferenced without checking if it passed the end of the matched string. This leads to a heap-based buffer over-read.An issue was discovered in Oniguruma 6.x before 6.9.4_rc2. In the function fetch_interval_quantifier in regparse.c, PFETCH is called without checking PEND. This leads to a heap-based buffer over-read.

Platform:
Alpine Linux 3.10
Alpine Linux 3.11
Alpine Linux 3.8
Alpine Linux 3.9
Product:
oniguruma
Reference:
11013
CVE-2019-19012
CVE-2019-19203
CVE-2019-19204
CVE-2019-19246
CVE    4
CVE-2019-19012
CVE-2019-19203
CVE-2019-19246
CVE-2019-19204
...

© SecPod Technologies