CVE-2019-19012

Description

An integer overflow in the search_in_range function in regexec.c in Oniguruma 6.x before 6.9.4_rc2 leads to an out-of-bounds read, in which the offset of this read is under the control of an attacker. (This only affects the 32-bit compiled version). Remote attackers can cause a denial-of-service or information disclosure, or possibly have unspecified other impact, via a crafted regular expression.

Risk Information

Base Score
9.8
MODERATE
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS Score
Exploitation Probability
14.783

Associated Vulnerability

VulnerabilityOS Platform
(RHSA-2024:0889)Moderate: security update oniguruma-6.8.2-2.1.el8_9.i686.rpmLinux
(RHSA-2024:0889)Moderate: security update oniguruma-6.8.2-2.1.el8_9.x86_64.rpmLinux
(RHSA-2024:0889)Moderate: security update oniguruma-debuginfo-6.8.2-2.1.el8_9.i686.rpmLinux
(RHSA-2024:0889)Moderate: security update oniguruma-debuginfo-6.8.2-2.1.el8_9.x86_64.rpmLinux
(RHSA-2024:0889)Moderate: security update oniguruma-debugsource-6.8.2-2.1.el8_9.i686.rpmLinux
(RHSA-2024:0889)Moderate: security update oniguruma-debugsource-6.8.2-2.1.el8_9.x86_64.rpmLinux
Oniguruma update (ELSA-2024-0889) oniguruma-6.8.2-2.1.el8_9.i686.rpmLinux
Oniguruma update (ELSA-2024-0889) oniguruma-6.8.2-2.1.el8_9.x86_64.rpmLinux
Rubygem-bundler update (ELSA-2025-7539) rubygem-bundler-1.16.1-5.module+el8.10.0+90580+29305b94.noarch.rpmLinux
Rubygem-bson-doc update (ELSA-2025-7539) rubygem-bson-doc-4.3.0-2.module+el8.9.0+90042+a65659a6.noarch.rpmLinux
Rubygem-bson update (ELSA-2025-7539) rubygem-bson-4.3.0-2.module+el8.9.0+90042+a65659a6.x86_64.rpmLinux
Rubygem-bigdecimal update (ELSA-2025-7539) rubygem-bigdecimal-1.3.4-114.module+el8.10.0+90580+29305b94.x86_64.rpmLinux
Rubygem-bigdecimal update (ELSA-2025-7539) rubygem-bigdecimal-1.3.4-114.module+el8.10.0+90580+29305b94.i686.rpmLinux
Rubygem-abrt-doc update (ELSA-2025-7539) rubygem-abrt-doc-0.3.0-4.module+el8.10.0+90367+ae9e8511.noarch.rpmLinux
Rubygem-abrt update (ELSA-2025-7539) rubygem-abrt-0.3.0-4.module+el8.10.0+90367+ae9e8511.noarch.rpmLinux
Ruby-libs update (ELSA-2025-7539) ruby-libs-2.5.9-114.module+el8.10.0+90580+29305b94.x86_64.rpmLinux
Ruby-libs update (ELSA-2025-7539) ruby-libs-2.5.9-114.module+el8.10.0+90580+29305b94.i686.rpmLinux
Ruby-irb update (ELSA-2025-7539) ruby-irb-2.5.9-114.module+el8.10.0+90580+29305b94.noarch.rpmLinux
Ruby-doc update (ELSA-2025-7539) ruby-doc-2.5.9-114.module+el8.10.0+90580+29305b94.noarch.rpmLinux
Ruby-devel update (ELSA-2025-7539) ruby-devel-2.5.9-114.module+el8.10.0+90580+29305b94.x86_64.rpmLinux
Ruby-devel update (ELSA-2025-7539) ruby-devel-2.5.9-114.module+el8.10.0+90580+29305b94.i686.rpmLinux
Ruby update (ELSA-2025-7539) ruby-2.5.9-114.module+el8.10.0+90580+29305b94.x86_64.rpmLinux
Ruby update (ELSA-2025-7539) ruby-2.5.9-114.module+el8.10.0+90580+29305b94.i686.rpmLinux
Rubygem-bundler-doc update (ELSA-2025-7539) rubygem-bundler-doc-1.16.1-5.module+el8.10.0+90580+29305b94.noarch.rpmLinux
Rubygems-devel update (ELSA-2025-7539) rubygems-devel-2.7.6.3-114.module+el8.10.0+90580+29305b94.noarch.rpmLinux
Rubygems update (ELSA-2025-7539) rubygems-2.7.6.3-114.module+el8.10.0+90580+29305b94.noarch.rpmLinux
Rubygem-xmlrpc update (ELSA-2025-7539) rubygem-xmlrpc-0.3.0-114.module+el8.10.0+90580+29305b94.noarch.rpmLinux
Rubygem-test-unit update (ELSA-2025-7539) rubygem-test-unit-3.2.7-114.module+el8.10.0+90580+29305b94.noarch.rpmLinux
Rubygem-rdoc update (ELSA-2025-7539) rubygem-rdoc-6.0.1.1-114.module+el8.10.0+90580+29305b94.noarch.rpmLinux
Rubygem-rake update (ELSA-2025-7539) rubygem-rake-12.3.3-114.module+el8.10.0+90580+29305b94.noarch.rpmLinux
Rubygem-psych update (ELSA-2025-7539) rubygem-psych-3.0.2-114.module+el8.10.0+90580+29305b94.x86_64.rpmLinux
Rubygem-psych update (ELSA-2025-7539) rubygem-psych-3.0.2-114.module+el8.10.0+90580+29305b94.i686.rpmLinux
Rubygem-power_assert update (ELSA-2025-7539) rubygem-power_assert-1.1.1-114.module+el8.10.0+90580+29305b94.noarch.rpmLinux
Rubygem-pg-doc update (ELSA-2025-7539) rubygem-pg-doc-1.0.0-3.module+el8.9.0+90042+a65659a6.noarch.rpmLinux
Rubygem-pg update (ELSA-2025-7539) rubygem-pg-1.0.0-3.module+el8.9.0+90042+a65659a6.x86_64.rpmLinux
Rubygem-did_you_mean update (ELSA-2025-7539) rubygem-did_you_mean-1.2.0-114.module+el8.10.0+90580+29305b94.noarch.rpmLinux
Rubygem-openssl update (ELSA-2025-7539) rubygem-openssl-2.1.2-114.module+el8.10.0+90580+29305b94.i686.rpmLinux
Rubygem-net-telnet update (ELSA-2025-7539) rubygem-net-telnet-0.1.1-114.module+el8.10.0+90580+29305b94.noarch.rpmLinux
Rubygem-mysql2-doc update (ELSA-2025-7539) rubygem-mysql2-doc-0.4.10-4.module+el8.9.0+90042+a65659a6.noarch.rpmLinux
Rubygem-mysql2 update (ELSA-2025-7539) rubygem-mysql2-0.4.10-4.module+el8.9.0+90042+a65659a6.x86_64.rpmLinux
Rubygem-mongo-doc update (ELSA-2025-7539) rubygem-mongo-doc-2.5.1-2.module+el8.9.0+90042+a65659a6.noarch.rpmLinux
Rubygem-mongo update (ELSA-2025-7539) rubygem-mongo-2.5.1-2.module+el8.9.0+90042+a65659a6.noarch.rpmLinux
Rubygem-minitest update (ELSA-2025-7539) rubygem-minitest-5.10.3-114.module+el8.10.0+90580+29305b94.noarch.rpmLinux
Rubygem-json update (ELSA-2025-7539) rubygem-json-2.1.0-114.module+el8.10.0+90580+29305b94.x86_64.rpmLinux
Rubygem-json update (ELSA-2025-7539) rubygem-json-2.1.0-114.module+el8.10.0+90580+29305b94.i686.rpmLinux
Rubygem-io-console update (ELSA-2025-7539) rubygem-io-console-0.4.6-114.module+el8.10.0+90580+29305b94.x86_64.rpmLinux
Rubygem-io-console update (ELSA-2025-7539) rubygem-io-console-0.4.6-114.module+el8.10.0+90580+29305b94.i686.rpmLinux
Rubygem-openssl update (ELSA-2025-7539) rubygem-openssl-2.1.2-114.module+el8.10.0+90580+29305b94.x86_64.rpmLinux
(RHSA-2025:7539)Moderate: security update rubygems-devel-2.7.6.3-114.module+el8.10.0+23088+750dc6ca.noarch.rpmLinux
(RHSA-2025:7539)Moderate: security update rubygems-2.7.6.3-114.module+el8.10.0+23088+750dc6ca.noarch.rpmLinux
(RHSA-2025:7539)Moderate: security update rubygem-xmlrpc-0.3.0-114.module+el8.10.0+23088+750dc6ca.noarch.rpmLinux
(RHSA-2025:7539)Moderate: security update rubygem-test-unit-3.2.7-114.module+el8.10.0+23088+750dc6ca.noarch.rpmLinux
(RHSA-2025:7539)Moderate: security update rubygem-rdoc-6.0.1.1-114.module+el8.10.0+23088+750dc6ca.noarch.rpmLinux
(RHSA-2025:7539)Moderate: security update rubygem-rake-12.3.3-114.module+el8.10.0+23088+750dc6ca.noarch.rpmLinux
(RHSA-2025:7539)Moderate: security update rubygem-psych-3.0.2-114.module+el8.10.0+23088+750dc6ca.x86_64.rpmLinux
(RHSA-2025:7539)Moderate: security update rubygem-psych-3.0.2-114.module+el8.10.0+23088+750dc6ca.i686.rpmLinux
(RHSA-2025:7539)Moderate: security update rubygem-power_assert-1.1.1-114.module+el8.10.0+23088+750dc6ca.noarch.rpmLinux
(RHSA-2025:7539)Moderate: security update rubygem-pg-doc-1.0.0-3.module+el8.9.0+19193+435404ae.noarch.rpmLinux
(RHSA-2025:7539)Moderate: security update rubygem-pg-1.0.0-3.module+el8.9.0+19193+435404ae.x86_64.rpmLinux
(RHSA-2025:7539)Moderate: security update rubygem-openssl-2.1.2-114.module+el8.10.0+23088+750dc6ca.x86_64.rpmLinux
(RHSA-2025:7539)Moderate: security update rubygem-openssl-2.1.2-114.module+el8.10.0+23088+750dc6ca.i686.rpmLinux
(RHSA-2025:7539)Moderate: security update rubygem-net-telnet-0.1.1-114.module+el8.10.0+23088+750dc6ca.noarch.rpmLinux
(RHSA-2025:7539)Moderate: security update rubygem-mysql2-doc-0.4.10-4.module+el8.9.0+19193+435404ae.noarch.rpmLinux
(RHSA-2025:7539)Moderate: security update rubygem-mysql2-0.4.10-4.module+el8.9.0+19193+435404ae.x86_64.rpmLinux
(RHSA-2025:7539)Moderate: security update rubygem-mongo-doc-2.5.1-2.module+el8.9.0+19193+435404ae.noarch.rpmLinux
(RHSA-2025:7539)Moderate: security update rubygem-mongo-2.5.1-2.module+el8.9.0+19193+435404ae.noarch.rpmLinux
(RHSA-2025:7539)Moderate: security update rubygem-minitest-5.10.3-114.module+el8.10.0+23088+750dc6ca.noarch.rpmLinux
(RHSA-2025:7539)Moderate: security update rubygem-json-2.1.0-114.module+el8.10.0+23088+750dc6ca.x86_64.rpmLinux
(RHSA-2025:7539)Moderate: security update rubygem-json-2.1.0-114.module+el8.10.0+23088+750dc6ca.i686.rpmLinux
(RHSA-2025:7539)Moderate: security update rubygem-io-console-0.4.6-114.module+el8.10.0+23088+750dc6ca.x86_64.rpmLinux
(RHSA-2025:7539)Moderate: security update rubygem-io-console-0.4.6-114.module+el8.10.0+23088+750dc6ca.i686.rpmLinux
(RHSA-2025:7539)Moderate: security update rubygem-did_you_mean-1.2.0-114.module+el8.10.0+23088+750dc6ca.noarch.rpmLinux
(RHSA-2025:7539)Moderate: security update rubygem-bundler-doc-1.16.1-5.module+el8.10.0+23088+750dc6ca.noarch.rpmLinux
(RHSA-2025:7539)Moderate: security update rubygem-bundler-1.16.1-5.module+el8.10.0+23088+750dc6ca.noarch.rpmLinux
(RHSA-2025:7539)Moderate: security update rubygem-bson-doc-4.3.0-2.module+el8.9.0+19193+435404ae.noarch.rpmLinux
(RHSA-2025:7539)Moderate: security update rubygem-bson-4.3.0-2.module+el8.9.0+19193+435404ae.x86_64.rpmLinux
(RHSA-2025:7539)Moderate: security update rubygem-bigdecimal-1.3.4-114.module+el8.10.0+23088+750dc6ca.x86_64.rpmLinux
(RHSA-2025:7539)Moderate: security update rubygem-bigdecimal-1.3.4-114.module+el8.10.0+23088+750dc6ca.i686.rpmLinux
(RHSA-2025:7539)Moderate: security update rubygem-abrt-doc-0.3.0-4.module+el8.10.0+22021+135c76a8.noarch.rpmLinux
(RHSA-2025:7539)Moderate: security update rubygem-abrt-0.3.0-4.module+el8.10.0+22021+135c76a8.noarch.rpmLinux
(RHSA-2025:7539)Moderate: security update ruby-libs-2.5.9-114.module+el8.10.0+23088+750dc6ca.x86_64.rpmLinux
(RHSA-2025:7539)Moderate: security update ruby-libs-2.5.9-114.module+el8.10.0+23088+750dc6ca.i686.rpmLinux
(RHSA-2025:7539)Moderate: security update ruby-irb-2.5.9-114.module+el8.10.0+23088+750dc6ca.noarch.rpmLinux
(RHSA-2025:7539)Moderate: security update ruby-doc-2.5.9-114.module+el8.10.0+23088+750dc6ca.noarch.rpmLinux
(RHSA-2025:7539)Moderate: security update ruby-devel-2.5.9-114.module+el8.10.0+23088+750dc6ca.x86_64.rpmLinux
(RHSA-2025:7539)Moderate: security update ruby-devel-2.5.9-114.module+el8.10.0+23088+750dc6ca.i686.rpmLinux
(RHSA-2025:7539)Moderate: security update ruby-2.5.9-114.module+el8.10.0+23088+750dc6ca.x86_64.rpmLinux
(RHSA-2025:7539)Moderate: security update ruby-2.5.9-114.module+el8.10.0+23088+750dc6ca.i686.rpmLinux
Moderate: ruby:2.5 security update ALSA-2025:7539 rubygems-devel-2.7.6.3-114.module_el8.10.0+3991+5e651d4e.noarch.rpmLinux
Moderate: ruby:2.5 security update ALSA-2025:7539 rubygems-2.7.6.3-114.module_el8.10.0+3991+5e651d4e.noarch.rpmLinux
Moderate: ruby:2.5 security update ALSA-2025:7539 rubygem-xmlrpc-0.3.0-114.module_el8.10.0+3991+5e651d4e.noarch.rpmLinux
Moderate: ruby:2.5 security update ALSA-2025:7539 rubygem-test-unit-3.2.7-114.module_el8.10.0+3991+5e651d4e.noarch.rpmLinux
Moderate: ruby:2.5 security update ALSA-2025:7539 rubygem-rdoc-6.0.1.1-114.module_el8.10.0+3991+5e651d4e.noarch.rpmLinux
Moderate: ruby:2.5 security update ALSA-2025:7539 rubygem-rake-12.3.3-114.module_el8.10.0+3991+5e651d4e.noarch.rpmLinux
Moderate: ruby:2.5 security update ALSA-2025:7539 rubygem-psych-3.0.2-114.module_el8.10.0+3991+5e651d4e.x86_64.rpmLinux
Moderate: ruby:2.5 security update ALSA-2025:7539 rubygem-psych-3.0.2-114.module_el8.10.0+3991+5e651d4e.i686.rpmLinux
Moderate: ruby:2.5 security update ALSA-2025:7539 rubygem-power_assert-1.1.1-114.module_el8.10.0+3991+5e651d4e.noarch.rpmLinux
Moderate: ruby:2.5 security update ALSA-2025:7539 rubygem-pg-doc-1.0.0-3.module_el8.9.0+3635+c6f99506.noarch.rpmLinux
Moderate: ruby:2.5 security update ALSA-2025:7539 rubygem-pg-1.0.0-3.module_el8.9.0+3635+c6f99506.x86_64.rpmLinux
Moderate: ruby:2.5 security update ALSA-2025:7539 rubygem-openssl-2.1.2-114.module_el8.10.0+3991+5e651d4e.x86_64.rpmLinux
Moderate: ruby:2.5 security update ALSA-2025:7539 rubygem-openssl-2.1.2-114.module_el8.10.0+3991+5e651d4e.i686.rpmLinux
Moderate: ruby:2.5 security update ALSA-2025:7539 rubygem-net-telnet-0.1.1-114.module_el8.10.0+3991+5e651d4e.noarch.rpmLinux
Moderate: ruby:2.5 security update ALSA-2025:7539 rubygem-mysql2-doc-0.4.10-4.module_el8.5.0+2625+ec418553.noarch.rpmLinux
Moderate: ruby:2.5 security update ALSA-2025:7539 rubygem-mysql2-0.4.10-4.module_el8.5.0+2625+ec418553.x86_64.rpmLinux
Moderate: ruby:2.5 security update ALSA-2025:7539 rubygem-mongo-doc-2.5.1-2.module_el8.5.0+2625+ec418553.noarch.rpmLinux
Moderate: ruby:2.5 security update ALSA-2025:7539 rubygem-mongo-2.5.1-2.module_el8.5.0+2625+ec418553.noarch.rpmLinux
Moderate: ruby:2.5 security update ALSA-2025:7539 rubygem-minitest-5.10.3-114.module_el8.10.0+3991+5e651d4e.noarch.rpmLinux
Moderate: ruby:2.5 security update ALSA-2025:7539 rubygem-json-2.1.0-114.module_el8.10.0+3991+5e651d4e.x86_64.rpmLinux
Moderate: ruby:2.5 security update ALSA-2025:7539 rubygem-json-2.1.0-114.module_el8.10.0+3991+5e651d4e.i686.rpmLinux
Moderate: ruby:2.5 security update ALSA-2025:7539 rubygem-io-console-0.4.6-114.module_el8.10.0+3991+5e651d4e.x86_64.rpmLinux
Moderate: ruby:2.5 security update ALSA-2025:7539 rubygem-io-console-0.4.6-114.module_el8.10.0+3991+5e651d4e.i686.rpmLinux
Moderate: ruby:2.5 security update ALSA-2025:7539 rubygem-did_you_mean-1.2.0-114.module_el8.10.0+3991+5e651d4e.noarch.rpmLinux
Moderate: ruby:2.5 security update ALSA-2025:7539 rubygem-bundler-doc-1.16.1-5.module_el8.10.0+3991+5e651d4e.noarch.rpmLinux
Moderate: ruby:2.5 security update ALSA-2025:7539 rubygem-bundler-1.16.1-5.module_el8.10.0+3991+5e651d4e.noarch.rpmLinux
Moderate: ruby:2.5 security update ALSA-2025:7539 rubygem-bson-doc-4.3.0-2.module_el8.5.0+2625+ec418553.noarch.rpmLinux
Moderate: ruby:2.5 security update ALSA-2025:7539 rubygem-bson-4.3.0-2.module_el8.5.0+2625+ec418553.x86_64.rpmLinux
Moderate: ruby:2.5 security update ALSA-2025:7539 rubygem-bigdecimal-1.3.4-114.module_el8.10.0+3991+5e651d4e.x86_64.rpmLinux
Moderate: ruby:2.5 security update ALSA-2025:7539 rubygem-bigdecimal-1.3.4-114.module_el8.10.0+3991+5e651d4e.i686.rpmLinux
Moderate: ruby:2.5 security update ALSA-2025:7539 rubygem-abrt-doc-0.3.0-4.module_el8.10.0+3871+342e2c2f.noarch.rpmLinux
Moderate: ruby:2.5 security update ALSA-2025:7539 rubygem-abrt-0.3.0-4.module_el8.5.0+2625+ec418553.noarch.rpmLinux
Moderate: ruby:2.5 security update ALSA-2025:7539 ruby-libs-2.5.9-114.module_el8.10.0+3991+5e651d4e.x86_64.rpmLinux
Moderate: ruby:2.5 security update ALSA-2025:7539 ruby-libs-2.5.9-114.module_el8.10.0+3991+5e651d4e.i686.rpmLinux
Moderate: ruby:2.5 security update ALSA-2025:7539 ruby-irb-2.5.9-114.module_el8.10.0+3991+5e651d4e.noarch.rpmLinux
Moderate: ruby:2.5 security update ALSA-2025:7539 ruby-doc-2.5.9-114.module_el8.10.0+3991+5e651d4e.noarch.rpmLinux
Moderate: ruby:2.5 security update ALSA-2025:7539 ruby-devel-2.5.9-114.module_el8.10.0+3991+5e651d4e.x86_64.rpmLinux
Moderate: ruby:2.5 security update ALSA-2025:7539 ruby-devel-2.5.9-114.module_el8.10.0+3991+5e651d4e.i686.rpmLinux
Moderate: ruby:2.5 security update ALSA-2025:7539 ruby-2.5.9-114.module_el8.10.0+3991+5e651d4e.x86_64.rpmLinux
Moderate: ruby:2.5 security update ALSA-2025:7539 ruby-2.5.9-114.module_el8.10.0+3991+5e651d4e.i686.rpmLinux
ruby:2.5 security update (RLSA-2025:7539) RLSA-2025:7539 rubygem-xmlrpc-0.3.0-114.module+el8.10.0+1979+815637df.noarch.rpmLinux
ruby:2.5 security update (RLSA-2025:7539) RLSA-2025:7539 rubygem-openssl-2.1.2-114.module+el8.10.0+1979+815637df.x86_64.rpmLinux
ruby:2.5 security update (RLSA-2025:7539) RLSA-2025:7539 rubygem-openssl-2.1.2-114.module+el8.10.0+1979+815637df.i686.rpmLinux
ruby:2.5 security update (RLSA-2025:7539) RLSA-2025:7539 rubygem-net-telnet-0.1.1-114.module+el8.10.0+1979+815637df.noarch.rpmLinux
ruby:2.5 security update (RLSA-2025:7539) RLSA-2025:7539 rubygem-mongo-doc-2.5.1-2.module+el8.9.0+1536+5f79634e.noarch.rpmLinux
ruby:2.5 security update (RLSA-2025:7539) RLSA-2025:7539 rubygem-mongo-2.5.1-2.module+el8.9.0+1536+5f79634e.noarch.rpmLinux
ruby:2.5 security update (RLSA-2025:7539) RLSA-2025:7539 rubygem-did_you_mean-1.2.0-114.module+el8.10.0+1979+815637df.noarch.rpmLinux
ruby:2.5 security update (RLSA-2025:7539) RLSA-2025:7539 rubygem-bundler-doc-1.16.1-5.module+el8.10.0+1979+815637df.noarch.rpmLinux
ruby:2.5 security update (RLSA-2025:7539) RLSA-2025:7539 rubygem-bson-doc-4.3.0-2.module+el8.9.0+1536+5f79634e.noarch.rpmLinux
ruby:2.5 security update (RLSA-2025:7539) RLSA-2025:7539 rubygem-bson-4.3.0-2.module+el8.9.0+1536+5f79634e.x86_64.rpmLinux
ruby:2.5 security update (RLSA-2025:7539) RLSA-2025:7539 ruby-irb-2.5.9-114.module+el8.10.0+1979+815637df.noarch.rpmLinux
Out-of-bounds Read Vulnerability (CVE-2019-19012)NCM

Patch Details

No records found

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234