An issue was discovered in Oniguruma 6.2.0, as used in Oniguruma-mod in Ruby through 2.4.1 and mbstring in PHP through 7.1.5. A stack out-of-bounds write in onigenc_unicode_get_case_fold_codes_by_str() occurs during regular expression compilation. Code point 0xFFFFFFFF is not properly handled in unicode_unfold_key(). A malformed regular expression could result in 4 bytes being written off the end of a stack buffer of expand_case_fold_string() during the call to onigenc_unicode_get_case_fold_codes_by_str(), a typical stack buffer overflow.
CVSS Details
- CVSS 3.0 Base Score: 9.8
- CVSS 3.0 Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade oniguruma | Sep 20, 2017 | May 24, 2017 |
| Amazon Linux Ami 2 | — | Upgrade php-fpmUpgrade php-processUpgrade php-debuginfoUpgrade php-commonUpgrade php-mbstringUpgrade php-dbaUpgrade php-xmlrpcUpgrade php-pgsqlUpgrade php-odbcUpgrade php-snmpUpgrade php-intlUpgrade php-xmlUpgrade php-mysqlndUpgrade php-jsonUpgrade php-ldapUpgrade php-dbgUpgrade php-cliUpgrade php-gmpUpgrade php-embeddedUpgrade php-develUpgrade phpUpgrade php-recodeUpgrade php-soapUpgrade php-gdUpgrade php-opcacheUpgrade php-bcmathUpgrade php-enchantUpgrade php-pspellUpgrade php-pdo | Jan 23, 2024 | May 24, 2017 |
| Debian | — | Upgrade libonig | Jul 30, 2024 | May 24, 2017 |
| Oracle Solaris | — | Upgrade library/oniguruma to version 6.1.1.1-11.4.2.0.1.2.0 on Solaris 11.4 | Oct 19, 2018 | May 24, 2017 |
| Ubuntu | — | Upgrade libonig | Nov 19, 2024 | May 24, 2017 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub