Do your applications use this vulnerable package?
Test your applications
Overview
Affected versions of this package are vulnerable to Out-of-bounds Write. In Oniguruma 6.9.5_rev1, an attacker able to supply a regular expression for compilation may be able to overflow a buffer by one byte in concat_opt_exact_str in src/regcomp.c .
Remediation
Upgrade oniguruma
to version or higher.
References
CVSS Score
8.6
high severity
-
Attack VectorNetwork
-
Attack ComplexityLow
-
Privileges RequiredNone
-
User InteractionNone
-
ScopeUnchanged
-
ConfidentialityLow
-
IntegrityLow
-
AvailabilityHigh
- CVE
- CVE-2020-26159
- CWE
- CWE-787
- Snyk ID
- SNYK-ALPINE39-ONIGURUMA-1017393
- Disclosed
- 30 Sep, 2020
- Published
- 14 Oct, 2020