Security update for oniguruma
This update for oniguruma fixes the following issues: - CVE-2019-19246: Fixed an out of bounds access during regular expression matching (bsc#1157805). - CVE-2019-19204: Fixed an out of bounds access when compiling a crafted regular expression (bsc#1164569). - CVE-2019-19203: Fixed an out of bounds access when performing a string search (bsc#1164550). - CVE-2019-16163: Fixed an uncontrolled recursion issue when compiling a crafted regular expression, which could lead to denial of service (bsc#1150130). - CVE-2020-26159: Fixed an off-by-one buffer overflow (bsc#1177179). - CVE-2019-13224: Fixed a potential use-after-free when handling multiple different encodings (bsc#1142847).
02 / AFFECTED SOFTWARE
Affected packages
03 / CONNECTIONS
Connected vulnerabilities
04 / EVIDENCE
Source records
This update for oniguruma fixes the following issues: - CVE-2019-19246: Fixed an out of bounds access during regular expression matching (bsc#1157805). - CVE-2019-19204: Fixed an out of bounds access when compiling a crafted regular expression (bsc#1164569). - CVE-2019-19203: Fixed an out of bounds access when performing a string search (bsc#1164550). - CVE-2019-16163: Fixed an uncontrolled recursion issue when compiling a crafted regular expression, which could lead to denial of service (bsc#1150130). - CVE-2020-26159: Fixed an off-by-one buffer overflow (bsc#1177179). - CVE-2019-13224: Fixed a potential use-after-free when handling multiple different encodings (bsc#1142847).
05 / REFERENCES
Further evidence
- https://bugzilla.suse.com/1142847
- https://bugzilla.suse.com/1150130
- https://bugzilla.suse.com/1157805
- https://bugzilla.suse.com/1164550
- https://bugzilla.suse.com/1164569
- https://bugzilla.suse.com/1177179
- https://www.suse.com/security/cve/CVE-2019-13224
- https://www.suse.com/security/cve/CVE-2019-16163
- https://www.suse.com/security/cve/CVE-2019-19203
- https://www.suse.com/security/cve/CVE-2019-19204
- https://www.suse.com/security/cve/CVE-2019-19246
- https://www.suse.com/security/cve/CVE-2020-26159
- https://www.suse.com/support/update/announcement/2022/suse-su-20223327-1/