Alerts This Week
Warning Icon 1 714
Alerts This Week
Warning Icon 1 714

Debian 8 LTS DLA-2020-1 Moderate: libonig Denial Of Service

debian lts
Calendar Grey December 4, 2019
Dist Debian Esm H88
Several security flaws in libonig could result in possible denial of service, necessitating an update for Debian 8.
Several vulnerabilities were discovered in the Oniguruma regular expressions library, notably used in PHP mbstring

Summary

CVE-2019-19012

An integer overflow in the search_in_range function in regexec.c
leads to an out-of-bounds read, in which the offset of this read
is under the control of an attacker. (This only affects the 32-bit
compiled version). Remote attackers can cause a denial-of-service
or information disclosure, or possibly have unspecified other
impact, via a crafted regular expression.

CVE-2019-19204

In the function fetch_range_quantifier in regparse.c, PFETCH is
called without checking PEND. This leads to a heap-based buffer
over-read and lead to denial-of-service via a crafted regular
expression.

CVE-2019-19246

Heap-based buffer over-read in str_lower_case_match in regexec.c
can lead to denial-of-service via a crafted regular expression.

For Debian 8 "Jessie", these problems have been fixed in version
5.9.5-3.2+deb8u4.

We recommend that you upgrade your libonig packages.

Further information about Debian LTS security advisories, how to apply

Read the Full Advisory


Package: libonig
Version: 5.9.5-3.2+deb8u4
CVE ID: CVE-2019-19012 CVE-2019-19204 CVE-2019-19246
Debian Bug: 944959 945313

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here