An issue was discovered in Oniguruma 6.2.0, as used in Oniguruma-mod in Ruby through 2.4.1 and mbstring in PHP through 7.1.5. A stack out-of-bounds write in onigenc_unicode_get_case_fold_codes_by_str() occurs during regular expression compilation. Code point 0xFFFFFFFF is not properly handled in unicode_unfold_key(). A malformed regular expression could result in 4 bytes being written off the end of a stack buffer of expand_case_fold_string() during the call to onigenc_unicode_get_case_fold_codes_by_str(), a typical stack buffer overflow.
CVSS Details
- CVSS 3.0 Base Score: 9.8
- CVSS 3.0 Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade oniguruma | Sep 20, 2017 | May 24, 2017 |
| Amazon Linux Ami 2 | — | Upgrade php-processUpgrade php-debuginfoUpgrade php-xmlrpcUpgrade php-fpmUpgrade php-commonUpgrade php-mbstringUpgrade php-dbaUpgrade php-pgsqlUpgrade php-odbcUpgrade php-ldapUpgrade php-snmpUpgrade php-opcacheUpgrade php-intlUpgrade php-pdoUpgrade php-mysqlndUpgrade php-xmlUpgrade php-jsonUpgrade php-embeddedUpgrade php-dbgUpgrade phpUpgrade php-gdUpgrade php-enchantUpgrade php-pspellUpgrade php-recodeUpgrade php-bcmathUpgrade php-gmpUpgrade php-soapUpgrade php-develUpgrade php-cli | Jan 23, 2024 | May 24, 2017 |
| Debian | — | Upgrade libonig | Jul 30, 2024 | May 24, 2017 |
| Oracle Solaris | — | Upgrade library/oniguruma to version 6.1.1.1-11.4.2.0.1.2.0 on Solaris 11.4 | Oct 19, 2018 | May 24, 2017 |
| Ubuntu | — | Upgrade libonig | Nov 19, 2024 | May 24, 2017 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub