CVE-2017-9225Out-of-bounds Write in Ruby

Severity
9.8CRITICALNVD
EPSS
0.3%
top 47.70%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedMay 24
Latest updateMay 17

Description

An issue was discovered in Oniguruma 6.2.0, as used in Oniguruma-mod in Ruby through 2.4.1 and mbstring in PHP through 7.1.5. A stack out-of-bounds write in onigenc_unicode_get_case_fold_codes_by_str() occurs during regular expression compilation. Code point 0xFFFFFFFF is not properly handled in unicode_unfold_key(). A malformed regular expression could result in 4 bytes being written off the end of a stack buffer of expand_case_fold_string() during the call to onigenc_unicode_get_case_fold_code

CVSS vector

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HExploitability: 3.9 | Impact: 5.9

Affected Packages3 packages

NVDruby-lang/ruby2.4.1
NVDphp/php7.1.5

Patches

🔴Vulnerability Details

3
GHSA
GHSA-24pf-h82m-5vvv: An issue was discovered in Oniguruma 62022-05-17
OSV
CVE-2017-9225: An issue was discovered in Oniguruma 62017-05-24
CVEList
CVE-2017-9225: An issue was discovered in Oniguruma 62017-05-24

📋Vendor Advisories

2
Red Hat
oniguruma: Out-of-bounds stack write in onigenc_unicode_get_case_fold_codes_by_str() during regular expression compilation2017-05-22
Debian
CVE-2017-9225: libonig - An issue was discovered in Oniguruma 6.2.0, as used in Oniguruma-mod in Ruby thr...2017

💬Community

5
Bugzilla
CVE-2017-9224 CVE-2017-9225 CVE-2017-9226 CVE-2017-9227 CVE-2017-9228 CVE-2017-9229 oniguruma: various flaws [fedora-all]2017-06-30
Bugzilla
CVE-2017-9224 CVE-2017-9225 CVE-2017-9226 CVE-2017-9227 CVE-2017-9228 CVE-2017-9229 php: various flaws [fedora-all]2017-06-30
Bugzilla
CVE-2017-9224 CVE-2017-9225 CVE-2017-9226 CVE-2017-9227 CVE-2017-9228 CVE-2017-9229 oniguruma: various flaws [epel-7]2017-06-30
Bugzilla
CVE-2017-9225 oniguruma: Out-of-bounds stack write in onigenc_unicode_get_case_fold_codes_by_str() during regular expression compilation2017-06-30
Bugzilla
CVE-2017-9224 CVE-2017-9225 CVE-2017-9226 CVE-2017-9227 CVE-2017-9228 CVE-2017-9229 ruby: various flaws [fedora-all]2017-06-30
CVE-2017-9225 — Out-of-bounds Write in Ruby-lang Ruby | cvebase