Out-of-bounds Write Affecting oniguruma package, versions <6.9.4-r1


low

Snyk CVSS

      Threat Intelligence

      EPSS 0.24% (64th percentile)
    Expand this section
    SUSE
    5.3 medium
    Expand this section
    Red Hat
    8.6 high

    Do your applications use this vulnerable package?

    In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

    Test your applications
    • Snyk ID SNYK-ALPINE311-ONIGURUMA-1017394
    • published 14 Oct 2020
    • disclosed 30 Sep 2020

    How to fix?

    Upgrade Alpine:3.11 oniguruma to version 6.9.4-r1 or higher.

    NVD Description

    Note: Versions mentioned in the description apply only to the upstream oniguruma package and not the oniguruma package as distributed by Alpine. See How to fix? for Alpine:3.11 relevant fixed versions and status.

    Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Further investigation showed that it was not a security issue. Notes: none