ALAS2-2023-2217

Related Vulnerabilities: CVE-2017-9224  

An issue was discovered in Oniguruma 6.2.0, as used in Oniguruma-mod in Ruby through 2.4.1 and mbstring in PHP through 7.1.5. A stack out-of-bounds read occurs in match_at() during regular expression searching. A logical error involving order of validation and access in match_at() could result in an out-of-bounds read from a stack buffer. (CVE-2017-9224)

ALAS2-2023-2217


Amazon Linux 2 Security Advisory: ALAS-2023-2217
Advisory Release Date: 2023-08-17 11:58 Pacific
Advisory Updated Date: 2023-08-23 00:18 Pacific
Severity: Medium

Issue Overview:

An issue was discovered in Oniguruma 6.2.0, as used in Oniguruma-mod in Ruby through 2.4.1 and mbstring in PHP through 7.1.5. A stack out-of-bounds read occurs in match_at() during regular expression searching. A logical error involving order of validation and access in match_at() could result in an out-of-bounds read from a stack buffer. (CVE-2017-9224)


Affected Packages:

oniguruma


Issue Correction:
Run yum update oniguruma to update your system.

New Packages:
aarch64:
    oniguruma-5.9.6-1.amzn2.0.5.aarch64
    oniguruma-devel-5.9.6-1.amzn2.0.5.aarch64
    oniguruma-debuginfo-5.9.6-1.amzn2.0.5.aarch64

i686:
    oniguruma-5.9.6-1.amzn2.0.5.i686
    oniguruma-devel-5.9.6-1.amzn2.0.5.i686
    oniguruma-debuginfo-5.9.6-1.amzn2.0.5.i686

src:
    oniguruma-5.9.6-1.amzn2.0.5.src

x86_64:
    oniguruma-5.9.6-1.amzn2.0.5.x86_64
    oniguruma-devel-5.9.6-1.amzn2.0.5.x86_64
    oniguruma-debuginfo-5.9.6-1.amzn2.0.5.x86_64