CVE-2019-20838
גבוהה 7.5
תיאור (מקור, אנגלית)
libpcre in PCRE before 8.43 allows a subject buffer over-read in JIT when UTF is disabled, and \X or \R has more than one fixed quantifier, a related issue to CVE-2019-20454.
מדדים
- CVSS 3.1
-
7.5 (HIGH)
מקור הציון: NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H - CWE
- CWE-125
מוצרים מושפעים
pcre: pcre; apple: macos; splunk: universal forwarder
קישורים
- https://support.apple.com/kb/HT211931 Vendor Advisory
- https://support.apple.com/kb/HT212147 Vendor Advisory
- https://www.pcre.org/original/changelog.txt Release NotesVendor Advisory
- https://support.apple.com/kb/HT211931 Vendor Advisory
- https://support.apple.com/kb/HT212147 Vendor Advisory
- https://www.pcre.org/original/changelog.txt Release NotesVendor Advisory
- https://bugs.gentoo.org/717920 Issue TrackingPatchThird Party AdvisoryVDB Entry
- https://bugs.gentoo.org/717920 Issue TrackingPatchThird Party AdvisoryVDB Entry
- http://seclists.org/fulldisclosure/2020/Dec/32 Mailing ListThird Party Advisory
- http://seclists.org/fulldisclosure/2021/Feb/14 Mailing ListThird Party Advisory