FlawAtlas
Search the atlas
SUSE-SU-2022:3327-1 Not scored

Security update for oniguruma

This update for oniguruma fixes the following issues: - CVE-2019-19246: Fixed an out of bounds access during regular expression matching (bsc#1157805). - CVE-2019-19204: Fixed an out of bounds access when compiling a crafted regular expression (bsc#1164569). - CVE-2019-19203: Fixed an out of bounds access when performing a string search (bsc#1164550). - CVE-2019-16163: Fixed an uncontrolled recursion issue when compiling a crafted regular expression, which could lead to denial of service (bsc#1150130). - CVE-2020-26159: Fixed an off-by-one buffer overflow (bsc#1177179). - CVE-2019-13224: Fixed a potential use-after-free when handling multiple different encodings (bsc#1142847).

Exploit probability Not scored
Published September 21, 2022
Required by Not available
Last source change February 4, 2026

02 / AFFECTED SOFTWARE

Affected packages

SUSE:Enterprise Storage 6 oniguruma
SUSE:Enterprise Storage 7 oniguruma
SUSE:Linux Enterprise High Performance Computing 15 SP1-ESPOS oniguruma
SUSE:Linux Enterprise High Performance Computing 15 SP1-LTSS oniguruma
SUSE:Linux Enterprise High Performance Computing 15 SP2-ESPOS oniguruma
SUSE:Linux Enterprise High Performance Computing 15 SP2-LTSS oniguruma
SUSE:Linux Enterprise Micro 5.1 oniguruma
SUSE:Linux Enterprise Micro 5.2 oniguruma
SUSE:Linux Enterprise Module for Basesystem 15 SP3 oniguruma
SUSE:Linux Enterprise Module for Basesystem 15 SP4 oniguruma
SUSE:Linux Enterprise Server 15 SP1-BCL oniguruma
SUSE:Linux Enterprise Server 15 SP1-LTSS oniguruma
SUSE:Linux Enterprise Server 15 SP2-BCL oniguruma
SUSE:Linux Enterprise Server 15 SP2-LTSS oniguruma
SUSE:Linux Enterprise Server for SAP Applications 15 SP1 oniguruma
SUSE:Linux Enterprise Server for SAP Applications 15 SP2 oniguruma
SUSE:Manager Proxy 4.1 oniguruma
SUSE:Manager Retail Branch Server 4.1 oniguruma
SUSE:Manager Server 4.1 oniguruma
openSUSE:Leap 15.3 oniguruma
openSUSE:Leap 15.4 oniguruma
openSUSE:Leap Micro 5.2 oniguruma

03 / CONNECTIONS

Connected vulnerabilities

04 / EVIDENCE

Source records

Open Source Vulnerabilities SUSE-SU-2022:3327-1

This update for oniguruma fixes the following issues: - CVE-2019-19246: Fixed an out of bounds access during regular expression matching (bsc#1157805). - CVE-2019-19204: Fixed an out of bounds access when compiling a crafted regular expression (bsc#1164569). - CVE-2019-19203: Fixed an out of bounds access when performing a string search (bsc#1164550). - CVE-2019-16163: Fixed an uncontrolled recursion issue when compiling a crafted regular expression, which could lead to denial of service (bsc#1150130). - CVE-2020-26159: Fixed an off-by-one buffer overflow (bsc#1177179). - CVE-2019-13224: Fixed a potential use-after-free when handling multiple different encodings (bsc#1142847).

View original source

05 / REFERENCES

Further evidence