SUSE-SU-2022:3327-1
Dashboard / Vulnerabilities / SUSE-SU-2022:3327-1
SUSE-SU-2022:3327-1
Summary: Security update for oniguruma
Details: This update for oniguruma fixes the following issues: - CVE-2019-19246: Fixed an out of bounds access during regular expression matching (bsc#1157805). - CVE-2019-19204: Fixed an out of bounds access when compiling a crafted regular expression (bsc#1164569). - CVE-2019-19203: Fixed an out of bounds access when performing a string search (bsc#1164550). - CVE-2019-16163: Fixed an uncontrolled recursion issue when compiling a crafted regular expression, which could lead to denial of service (bsc#1150130). - CVE-2020-26159: Fixed an off-by-one buffer overflow (bsc#1177179). - CVE-2019-13224: Fixed a potential use-after-free when handling multiple different encodings (bsc#1142847).
References: https://www.suse.com/support/update/announcement/2022/suse-su-20223327-1/, https://bugzilla.suse.com/1142847, https://bugzilla.suse.com/1150130, https://bugzilla.suse.com/1157805, https://bugzilla.suse.com/1164550, https://bugzilla.suse.com/1164569, https://bugzilla.suse.com/1177179, https://www.suse.com/security/cve/CVE-2019-13224, https://www.suse.com/security/cve/CVE-2019-16163, https://www.suse.com/security/cve/CVE-2019-19203, https://www.suse.com/security/cve/CVE-2019-19204, https://www.suse.com/security/cve/CVE-2019-19246, https://www.suse.com/security/cve/CVE-2020-26159
Affected packages
Package
Name: oniguruma
Purl: pkg:rpm/suse/oniguruma&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Basesystem%2015%20SP3
Affected ranges
Type: ECOSYSTEM
Events:
