CVE-2019-9023: Buffer Overflow
An issue was discovered in PHP before 5.6.40, 7.x before 7.1.26, 7.2.x before 7.2.14, and 7.3.x before 7.3.1. A number of heap-based buffer over-read instances are present in mbstring regular expression functions when supplied with invalid multibyte data. These occur in ext/mbstring/oniguruma/regcomp.c, ext/mbstring/oniguruma/regexec.c, ext/mbstring/oniguruma/regparse.c, ext/mbstring/oniguruma/enc/unicode.c, and ext/mbstring/oniguruma/src/utf32be.c when a multibyte regular expression pattern contains invalid multibyte sequences.
Other sources
Fixed bug (Buffer overflow in multibyte case folding - unicode). (CVE-2019-9023)
— PHP
Affected Software
Remediation
Patch Available
Patch Available
Patch Available
Patch Available
Patch Available
Patch Available
Patch Available
Patch Available
Event History
Parent advisories
This vulnerability appears in the following advisories.
Frequently Asked Questions
What is the vulnerability ID for this bug?
The vulnerability ID for this bug is CVE-2019-9023.
What is the severity of CVE-2019-9023?
The severity of CVE-2019-9023 is critical with a score of 9.8.
What is the affected software for CVE-2019-9023?
The affected software for CVE-2019-9023 includes PHP versions before 5.6.40, 7.x before 7.1.26, 7.2.x before 7.2.14, and 7.3.x before 7.3.1.
What is the fix for CVE-2019-9023?
To fix CVE-2019-9023, update PHP to version 5.6.40, 7.1.26, 7.2.14, or 7.3.1.
Where can I find more information about CVE-2019-9023?
You can find more information about CVE-2019-9023 at the following links: [Link 1](https://www.php.net/ChangeLog-7.php#7.1.26), [Link 2](http://git.php.net/?p=php-src.git;a=commit;h=20407d06ca3cb5eeb10f876a812b40c381574bcc), [Link 3](http://git.php.net/?p=php-src.git;a=commit;h=deb06bbb9cbb31292fc219501614a8c3ff25bb11).