CVE-2019-19012: Integer Overflow
An integer overflow in the searchinrange function in regexec.c in Oniguruma 6.x before 6.9.4rc2 leads to an out-of-bounds read, in which the offset of this read is under the control of an attacker. (This only affects the 32-bit compiled version). Remote attackers can cause a denial-of-service or information disclosure, or possibly have unspecified other impact, via a crafted regular expression.
Other sources
Oniguruma is vulnerable to a denial of service, caused by an integer overflow in the searchinrange function in regexec.c. By using a specially crafted regular expression, a local attacker could exploit this vulnerability to cause the application to crash or obtain sensitive information.
— IBM
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the vulnerability ID for this issue?
The vulnerability ID for this issue is CVE-2019-19012.
What is the severity of CVE-2019-19012?
The severity of CVE-2019-19012 is critical with a severity value of 9.8.
What is the affected software for CVE-2019-19012?
The affected software for CVE-2019-19012 includes Oniguruma versions between 6.0.0 and 6.9.3, Oniguruma 6.9.4-rc1, Debian Linux 8.0, Fedora 30 and 31, Red Hat Enterprise Linux 8.0, and libonig packages in Ubuntu and Debian.
How does CVE-2019-19012 impact the system?
CVE-2019-19012 can lead to a denial-of-service or out-of-bounds read, which can be exploited by remote attackers.
How can CVE-2019-19012 be fixed?
To fix CVE-2019-19012, it is recommended to upgrade to Oniguruma version 6.9.4-rc2 or later, or follow the remediation steps provided by the relevant software vendors.