CVE-2019-13225NULL Pointer Dereference in Project Oniguruma

Severity
6.5MEDIUMNVD
EPSS
0.1%
top 66.99%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJul 10
Latest updateMay 24

Description

A NULL Pointer Dereference in match_at() in regexec.c in Oniguruma 6.9.2 allows attackers to potentially cause denial of service by providing a crafted regular expression. Oniguruma issues often affect Ruby, as well as common optional libraries for PHP and Rust.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:HExploitability: 2.8 | Impact: 3.6

Affected Packages1 packages

Also affects: Fedora 29, 30

Patches

🔴Vulnerability Details

3
GHSA
GHSA-cc6v-h3w4-jf38: A NULL Pointer Dereference in match_at() in regexec2022-05-24
OSV
CVE-2019-13225: A NULL Pointer Dereference in match_at() in regexec2019-07-10
CVEList
CVE-2019-13225: A NULL Pointer Dereference in match_at() in regexec2019-07-10

📋Vendor Advisories

2
Red Hat
oniguruma: NULL pointer dereference in match_at() in regexec.c2019-06-27
Debian
CVE-2019-13225: libonig - A NULL Pointer Dereference in match_at() in regexec.c in Oniguruma 6.9.2 allows ...2019

💬Community

3
Bugzilla
CVE-2019-13225 oniguruma: NULL pointer dereference in match_at() in regexec.c2019-07-11
Bugzilla
CVE-2019-13225 oniguruma: null-pointer dereference in match_at() in regexec.c [epel-7]2019-07-11
Bugzilla
CVE-2019-13225 oniguruma: null-pointer dereference in match_at() in regexec.c [fedora-all]2019-07-11
CVE-2019-13225 — NULL Pointer Dereference | cvebase