First published: Tue Feb 26 2019(Updated: )
** DISPUTED ** In the GNU C Library (aka glibc or libc6) through 2.29, check_dst_limits_calc_pos_1 in posix/regexec.c has Uncontrolled Recursion, as demonstrated by '(|)(\\1\\1)*' in grep, a different issue than CVE-2018-20796. NOTE: the software maintainer disputes that this is a vulnerability because the behavior occurs only with a crafted pattern.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
GNU glibc | <=2.29 | |
<=2.29 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2019-9192 is a vulnerability in the GNU C Library (glibc) that allows for uncontrolled recursion.
CVE-2019-9192 has a severity score of 7.5 (high).
CVE-2019-9192 affects GNU C Library (glibc) versions up to 2.29.
CVE-2019-9192 allows attackers to cause a denial of service or potentially execute arbitrary code.
As of now, there is no official fix or patch available for CVE-2019-9192. It is recommended to keep systems up to date with the latest security patches and monitor for any vendor updates.