RHSA-2024:0572MediumCVSS 7.5
Red Hat Security Advisory: oniguruma security update
🔗 CVE IDs covered (5)
📋 Description
CVE-2019-13224 — oniguruma: Use-after-free in onig_new_deluxe() in regext.c CVE-2019-16163 — oniguruma: Stack exhaustion in regcomp.c because of recursion in regparse.c CVE-2019-19012 — oniguruma: integer overflow in search_in_range function in regexec.c leads to out-of-bounds read CVE-2019-19203 — oniguruma: Heap-based buffer over-read in function gb18030_mbc_enc_len in file gb18030.c CVE-2019-19204 — oniguruma: Heap-based buffer over-read in function fetch_interval_quantifier in regparse.c
🔗 References (8)
- selfhttps://access.redhat.com/errata/RHSA-2024:0572
- externalhttps://access.redhat.com/security/updates/classification/#moderate
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1728970
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1768997
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1802051
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1802061
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1802068
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2024/rhsa-2024_0572.json