UBUNTU-CVE-2019-19012
Dashboard / Vulnerabilities / UBUNTU-CVE-2019-19012
UBUNTU-CVE-2019-19012
Summary:
Details: An integer overflow in the search_in_range function in regexec.c in Oniguruma 6.x before 6.9.4_rc2 leads to an out-of-bounds read, in which the offset of this read is under the control of an attacker. (This only affects the 32-bit compiled version). Remote attackers can cause a denial-of-service or information disclosure, or possibly have unspecified other impact, via a crafted regular expression.
References: https://ubuntu.com/security/CVE-2019-19012, https://github.com/kkos/oniguruma/issues/164, https://github.com/kkos/oniguruma/releases/tag/v6.9.4_rc2, https://ubuntu.com/security/notices/USN-4460-1, https://ubuntu.com/security/notices/USN-5662-1, https://www.cve.org/CVERecord?id=CVE-2019-19012
Affected packages
Package
Name: libonig
Purl: pkg:deb/ubuntu/[email protected]+esm2?arch=source&distro=trusty/esm
Affected ranges
Type: ECOSYSTEM
Events:
