Alerts This Week
Warning Icon 1 914
Alerts This Week
Warning Icon 1 914

Debian 9 DLA-2431-2 Moderate: libonig Buffer Overflow Reversion

debian lts
Calendar Grey January 30, 2021
Dist Debian Esm H88
Debian LTS Advisory DLA-2432-1 addresses an issue with libxml2, advising users to update their packages to enhance security.
It was discovered that CVE-2020-26159 in the Oniguruma regular expressions library, notably used in PHP mbstring, was a false-positive

Summary

In Oniguruma an attacker able to supply a regular expression for
compilation may be able to overflow a buffer by one byte in
concat_opt_exact_str in src/regcomp.c

For Debian 9 stretch, this problem has been fixed in version
6.1.3-2+deb9u2.

We recommend that you upgrade your libonig packages.

For the detailed security status of libonig please refer to
its security tracker page at:
https://security-tracker.debian.org/tracker/source-package/libonig

Further information about Debian LTS security advisories, how to apply
these updates to your system and frequently asked questions can be
found at: https://wiki.debian.org/LTS


-------------------------------------------------------------------------Package: libonig
Version: 6.1.3-2+deb9u2
CVE ID: CVE-2020-26159

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here