CVE-2019-19012
An integer overflow in the search_in_range function in regexec.c in Oniguruma 6.x before 6.9.4_rc2 leads to an out-of-bounds read, in which the offset of this read is under the control of an attacker.
Does this matter?
EPSS puts the probability of exploitation in the next 30 days at 10.5%, higher than 96% of all known CVEs. Patch or mitigate before the next change window.
Description
An integer overflow in the search_in_range function in regexec.c in Oniguruma 6.x before 6.9.4_rc2 leads to an out-of-bounds read, in which the offset of this read is under the control of an attacker. (This only affects the 32-bit compiled version). Remote attackers can cause a denial-of-service or information disclosure, or possibly have unspecified other impact, via a crafted regular expression.
- CVSS 3.1
- 9.8 CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 10.54% probability · 96th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-125, CWE-190
- Affected
- oniguruma project/oniguruma · debian/debian linux · fedoraproject/fedora · redhat/enterprise linux
- Source
- cve@mitre.org
References
- https://github.com/kkos/oniguruma/issues/164Exploit, Patch, Third Party Advisory
- https://github.com/kkos/oniguruma/releases/tag/v6.9.4_rc2Third Party Advisory
- https://github.com/tarantula-team/CVE-2019-19012Exploit, Third Party Advisory
- https://lists.debian.org/debian-lts-announce/2019/12/msg00002.htmlThird Party Advisory
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/NO267PLHGYZSWX3XTRPKYBKD4J3YOU5V/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/V3MBNW6Z4DOXSCNWGBLQ7OA3OGUJ44WL/
- https://usn.ubuntu.com/4460-1/
- https://github.com/kkos/oniguruma/issues/164Exploit, Patch, Third Party Advisory
- https://github.com/kkos/oniguruma/releases/tag/v6.9.4_rc2Third Party Advisory
- https://github.com/tarantula-team/CVE-2019-19012Exploit, Third Party Advisory
- https://lists.debian.org/debian-lts-announce/2019/12/msg00002.htmlThird Party Advisory
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/NO267PLHGYZSWX3XTRPKYBKD4J3YOU5V/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/V3MBNW6Z4DOXSCNWGBLQ7OA3OGUJ44WL/
- https://usn.ubuntu.com/4460-1/
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.