CVE-2020-11958Out-of-bounds Write in Re2c

Severity
7.8HIGHNVD
EPSS
0.6%
top 30.98%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedApr 21
Latest updateMay 24

Description

re2c 1.3 has a heap-based buffer overflow in Scanner::fill in parse/scanner.cc via a long lexeme.

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:HExploitability: 1.8 | Impact: 5.9

Affected Packages2 packages

Debianre2c/re2c< 1.3-2+3
NVDre2c/re2c1.3

Also affects: Ubuntu Linux 19.10, 20.04

Patches

🔴Vulnerability Details

3
GHSA
GHSA-qvw2-729q-g92x: re2c 12022-05-24
OSV
CVE-2020-11958: re2c 12020-04-21
CVEList
CVE-2020-11958: re2c 12020-04-21

📋Vendor Advisories

4
Ubuntu
re2c vulnerability2020-04-28
Ubuntu
re2c vulnerability2020-04-22
Red Hat
re2c: heap-based buffer overflow in Scanner::fill in parse/scanner.cc2020-04-17
Debian
CVE-2020-11958: re2c - re2c 1.3 has a heap-based buffer overflow in Scanner::fill in parse/scanner.cc v...2020

💬Community

1
Bugzilla
CVE-2020-11958 re2c: heap-based buffer overflow in Scanner::fill in parse/scanner.cc2020-04-22
CVE-2020-11958 — Out-of-bounds Write in Re2c | cvebase