First published: Sun Jul 28 2019(Updated: )
Last updated 24 July 2024
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Oniguruma Project Oniguruma | <6.9.3 | |
Fedoraproject Fedora | =29 | |
Fedoraproject Fedora | =30 | |
Debian Debian Linux | =8.0 | |
Canonical Ubuntu Linux | =14.04 | |
IBM IBM® Db2® on Cloud Pak for Data and Db2 Warehouse on Cloud Pak for Data | <=v3.5 through refresh 10v4.0 through refresh 9v4.5 through refresh 3v4.6 through refresh 6v4.7 through refresh 4v4.8 through refresh 4 | |
debian/libonig | 6.9.6-1.1 6.9.8-1 6.9.9-1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2019-16163 is a vulnerability in Oniguruma before 6.9.3 that allows stack exhaustion due to recursion.
CVE-2019-16163 has a severity rating of 7.5 (High).
CVE-2019-16163 affects Oniguruma before version 6.9.3, Fedora versions 29 and 30, Debian Linux version 8.0, and Ubuntu Linux version 14.04.
You can find more information about CVE-2019-16163 on the following references: [link1](https://github.com/kkos/oniguruma/issues/147), [link2](https://github.com/kkos/oniguruma/commit/4097828d7cc87589864fecf452f2cd46c5f37180), [link3](https://bugzilla.redhat.com/show_bug.cgi/show_bug.cgi?id=1768999).
To fix CVE-2019-16163, update to Oniguruma version 6.9.3 or higher.