[Forgot Password]
Login  Register Subscribe

30479

 
 

423868

 
 

250108

 
 

909

 
 

196064

 
 

282

Paid content will be excluded from the download.


Download | Alert*
OVAL

ALAS2-2020-1380 --- oniguruma

ID: oval:org.secpod.oval:def:1700292Date: (C)2020-01-14   (M)2023-11-13
Class: PATCHFamily: unix




Oniguruma before 6.9.3 allows Stack Exhaustion in regcomp.c because of recursion in regparse.c. Oniguruma through 6.9.3, as used in PHP 7.3.x and other products, has a heap-based buffer over-read in str_lower_case_match in regexec.c.

Platform:
Amazon Linux 2
Product:
oniguruma
Reference:
ALAS2-2020-1380
CVE-2019-19246
CVE-2019-19012
CVE-2019-19204
CVE-2019-16163
CVE    4
CVE-2019-19012
CVE-2019-16163
CVE-2019-19246
CVE-2019-19204
...
CPE    2
cpe:/a:github:oniguruma
cpe:/o:amazon:linux:2

© SecPod Technologies