7.5
CVSSv3

CVE-2019-19246

Published: 25/11/2019 Updated: 07/11/2023
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
CVSS v3 Base Score: 7.5 | Impact Score: 3.6 | Exploitability Score: 3.9
VMScore: 447
Vector: AV:N/AC:L/Au:N/C:N/I:N/A:P

Vulnerability Summary

Oniguruma up to and including 6.9.3, as used in PHP 7.3.x and other products, has a heap-based buffer over-read in str_lower_case_match in regexec.c.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

oniguruma project oniguruma

php php

fedoraproject fedora 31

canonical ubuntu linux 14.04

debian debian linux 8.0

Vendor Advisories

Debian Bug report logs - #946344 libonig: CVE-2019-19246 Package: src:libonig; Maintainer for src:libonig is Jörg Frings-Fürst <debian@jffemail>; Reported by: Salvatore Bonaccorso <carnil@debianorg> Date: Sat, 7 Dec 2019 15:42:01 UTC Severity: important Tags: security, upstream Found in versions libonig/691-1 ...
Synopsis Moderate: rh-php73-php security, bug fix, and enhancement update Type/Severity Security Advisory: Moderate Topic An update for rh-php73-php is now available for Red Hat Software CollectionsRed Hat Product Security has rated this update as having a security impact of Moderate A Common Vulnerabilit ...
Synopsis Moderate: php:73 security, bug fix, and enhancement update Type/Severity Security Advisory: Moderate Topic An update for the php:73 module is now available for Red Hat Enterprise Linux 8Red Hat Product Security has rated this update as having a security impact of Moderate A Common Vulnerability ...
Oniguruma before 693 allows Stack Exhaustion in regcompc because of recursion in regparsec (CVE-2019-16163) Oniguruma through 693, as used in PHP 73x and other products, has a heap-based buffer over-read in str_lower_case_match in regexecc(CVE-2019-19246) ...