Oniguruma: Multiple vulnerabilities CVE-2019-19012, CVE-2019-19203, CVE-2019-19204, CVE-2019-19246)ID: oval:org.secpod.oval:def:1801662 | Date: (C)2020-01-14 (M)2023-11-10 |
Class: PATCH | Family: unix |
Oniguruma through 6.9.3, as used in PHP 7.3.x and other products, has a heap-based buffer over-read in str_lower_case_match in regexec.c.An issue was discovered in Oniguruma 6.x before 6.9.4_rc2. In the function gb18030_mbc_enc_len in file gb18030.c, a UChar pointer is dereferenced without checking if it passed the end of the matched string. This leads to a heap-based buffer over-read.An issue was discovered in Oniguruma 6.x before 6.9.4_rc2. In the function fetch_interval_quantifier in regparse.c, PFETCH is called without checking PEND. This leads to a heap-based buffer over-read.
Platform: |
Alpine Linux 3.10 |
Alpine Linux 3.11 |
Alpine Linux 3.8 |
Alpine Linux 3.9 |