Oniguruma through 6.9.3, as used in PHP 7.3.x and other products, has a heap-based buffer over-read in str_lower_case_match in regexec.c.
History

Fri, 14 Feb 2025 01:45:00 +0000

Type Values Removed Values Added
Metrics cvssV3_0

{'score': 4.8, 'vector': 'CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:L'}

threat_severity

Low

cvssV3_0

{'score': 6.5, 'vector': 'CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:H'}

threat_severity

Moderate


cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2024-08-05T02:09:39.638Z

Reserved: 2019-11-25T00:00:00

Link: CVE-2019-19246

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2019-11-25T17:15:11.887

Modified: 2024-11-21T04:34:24.357

Link: CVE-2019-19246

cve-icon Redhat

Severity : Moderate

Publid Date: 2019-08-13T00:00:00Z

Links: CVE-2019-19246 - Bugzilla