Record summary

CVE-2019-19204 has a selected CVSS score of 7.5 (high); EIP currently links 2 repository PoCs.

Description

An issue was discovered in Oniguruma 6.x before 6.9.4_rc2. In the function fetch_interval_quantifier (formerly known as fetch_range_quantifier) in regparse.c, PFETCH is called without checking PEND. This leads to a heap-based buffer over-read.

Description source: CVE List

Exploitation context

Available material

Repository PoCs
2

Proofs of concept

2

Repository PoCs

GitHubManhNDd/CVE-2019-19204Repository PoCby ManhNDdStars: 3Not analyzed1 file

5.4 KiB

GitHub

PoC details
GitHubtarantula-team/CVE-2019-19204Repository PoCby tarantula-teamStars: 0Not analyzed1 file

5.4 KiB

GitHub

PoC details

References

11