Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2019-13225

Опубликовано: 27 июн. 2019
Источник: redhat
CVSS3: 5.3
EPSS Низкий

Описание

A NULL Pointer Dereference in match_at() in regexec.c in Oniguruma 6.9.2 allows attackers to potentially cause denial of service by providing a crafted regular expression. Oniguruma issues often affect Ruby, as well as common optional libraries for PHP and Rust.

Отчет

The version of Oniguruma package as shipped with Red Hat Enterprise Linux 6 is not affected by this issue. The issue resides on the way 'If/Else' statements are handled by Oniguruma which is not supported by Red Hat Enterprise Linux 6.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 5phpNot affected
Red Hat Enterprise Linux 5php53Not affected
Red Hat Enterprise Linux 6onigurumaNot affected
Red Hat Enterprise Linux 6phpNot affected
Red Hat Enterprise Linux 7phpNot affected
Red Hat Enterprise Linux 8php:7.2/phpNot affected
Red Hat Enterprise Linux 8ruby:2.5/rubyNot affected
Red Hat Enterprise Linux 8ruby:2.6/rubyNot affected
Red Hat OpenShift Container Platform 4onigurumaNot affected
Red Hat Software Collectionsrh-php70-phpNot affected

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-476->CWE-400
https://bugzilla.redhat.com/show_bug.cgi?id=1728965oniguruma: NULL pointer dereference in match_at() in regexec.c

EPSS

Процентиль: 32%
0.00118
Низкий

5.3 Medium

CVSS3

Связанные уязвимости

CVSS3: 6.5
ubuntu
почти 6 лет назад

A NULL Pointer Dereference in match_at() in regexec.c in Oniguruma 6.9.2 allows attackers to potentially cause denial of service by providing a crafted regular expression. Oniguruma issues often affect Ruby, as well as common optional libraries for PHP and Rust.

CVSS3: 6.5
nvd
почти 6 лет назад

A NULL Pointer Dereference in match_at() in regexec.c in Oniguruma 6.9.2 allows attackers to potentially cause denial of service by providing a crafted regular expression. Oniguruma issues often affect Ruby, as well as common optional libraries for PHP and Rust.

CVSS3: 6.5
debian
почти 6 лет назад

A NULL Pointer Dereference in match_at() in regexec.c in Oniguruma 6.9 ...

suse-cvrf
11 месяцев назад

Security update for oniguruma

rocky
больше 4 лет назад

Moderate: oniguruma security update

EPSS

Процентиль: 32%
0.00118
Низкий

5.3 Medium

CVSS3