An issue was discovered in Oniguruma 6.x before 6.9.4_rc2. In the function fetch_interval_quantifier (formerly known as fetch_range_quantifier) in regparse.c, PFETCH is called without checking PEND. This leads to a heap-based buffer over-read.
References
Configurations
Configuration 1 (hide)
|
Configuration 2 (hide)
|
History
No history.
Information
Published : 2019-11-21 21:15
Updated : 2024-11-21 04:34
NVD link : CVE-2019-19204
Mitre link : CVE-2019-19204
CVE.ORG link : CVE-2019-19204
JSON object : View
Products Affected
oniguruma_project
- oniguruma
debian
- debian_linux
fedoraproject
- fedora
CWE
CWE-125
Out-of-bounds Read