ALAS2-2020-1560

Related Vulnerabilities: CVE-2020-26159  

In Oniguruma 6.9.5_rev1, an attacker able to supply a regular expression for compilation may be able to overflow a buffer by one byte in concat_opt_exact_str in src/regcomp.c . (CVE-2020-26159)

ALAS2-2020-1560


Amazon Linux 2 Security Advisory: ALAS-2020-1560
Advisory Release Date: 2020-11-09 21:04 Pacific
Advisory Updated Date: 2020-11-11 17:42 Pacific
Severity: Medium
References: CVE-2020-26159 

Issue Overview:

In Oniguruma 6.9.5_rev1, an attacker able to supply a regular expression for compilation may be able to overflow a buffer by one byte in concat_opt_exact_str in src/regcomp.c . (CVE-2020-26159)


Affected Packages:

oniguruma


Issue Correction:
Run yum update oniguruma to update your system.

New Packages:
aarch64:
    oniguruma-5.9.6-1.amzn2.0.4.aarch64
    oniguruma-devel-5.9.6-1.amzn2.0.4.aarch64
    oniguruma-debuginfo-5.9.6-1.amzn2.0.4.aarch64

i686:
    oniguruma-5.9.6-1.amzn2.0.4.i686
    oniguruma-devel-5.9.6-1.amzn2.0.4.i686
    oniguruma-debuginfo-5.9.6-1.amzn2.0.4.i686

src:
    oniguruma-5.9.6-1.amzn2.0.4.src

x86_64:
    oniguruma-5.9.6-1.amzn2.0.4.x86_64
    oniguruma-devel-5.9.6-1.amzn2.0.4.x86_64
    oniguruma-debuginfo-5.9.6-1.amzn2.0.4.x86_64