CVE-2019-19246 — Out-of-bounds Read in Project Oniguruma
Severity
7.5HIGHNVD
EPSS
0.3%
top 44.99%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedNov 25
Latest updateOct 10
Description
Oniguruma through 6.9.3, as used in PHP 7.3.x and other products, has a heap-based buffer over-read in str_lower_case_match in regexec.c.
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:HExploitability: 3.9 | Impact: 3.6
Affected Packages2 packages
Also affects: Debian Linux 8.0, Fedora 31, Ubuntu Linux 14.04
Patches
🔴Vulnerability Details
5📋Vendor Advisories
4Debian▶
CVE-2019-19246: libonig - Oniguruma through 6.9.3, as used in PHP 7.3.x and other products, has a heap-bas...↗2019
💬Community
4Bugzilla▶
CVE-2019-19246 oniguruma: Heap-based buffer overflow in str_lower_case_match in regexec.c↗2019-11-27
Bugzilla▶
CVE-2019-19246 oniguruma: heap-based buffer overflow in str_lower_case_match in regexec.c [epel-7]↗2019-11-27
Bugzilla▶
CVE-2019-19246 oniguruma: heap-based buffer overflow in str_lower_case_match in regexec.c [openstack-rdo]↗2019-11-27
Bugzilla▶
CVE-2019-19246 oniguruma: heap-based buffer overflow in str_lower_case_match in regexec.c [fedora-all]↗2019-11-27