Record summary

CVE-2019-19012 has a selected CVSS score of 9.8 (critical); EIP currently links 2 repository PoCs.

Description

An integer overflow in the search_in_range function in regexec.c in Oniguruma 6.x before 6.9.4_rc2 leads to an out-of-bounds read, in which the offset of this read is under the control of an attacker. (This only affects the 32-bit compiled version). Remote attackers can cause a denial-of-service or information disclosure, or possibly have unspecified other impact, via a crafted regular expression.

Description source: CVE List

Exploitation context

Available material

Repository PoCs
2

Proofs of concept

2

Repository PoCs

GitHubManhNDd/CVE-2019-19012Repository PoCby ManhNDdStars: 4Not analyzed3 files

1.4 MiB

GitHub

PoC details
GitHubtarantula-team/CVE-2019-19012Repository PoCby tarantula-teamStars: 0Not analyzed1 file

9.8 KiB

GitHub

PoC details

References

10