Use-after-free in Oniguruma - CVE-2019-13224

 

Use-after-free in Oniguruma - CVE-2019-13224

Published: September 6, 2019


Vulnerability identifier: #VU20904
CSH Severity: High
CVSS v4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2019-13224
CWE-ID: CWE-416
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to compromise vulnerable system.

The vulnerability exists due to a use-after-free error within the onig_new_deluxe() function in regext.c in Oniguruma library when processing regular expressions. A remote attacker can pass specially crafted input to the application using the vulnerable library version, trigger use-after-free error and perform denial of service attack or execute arbitrary code on the system.

Successful exploitation of the vulnerability may allow an attacker to compromise vulnerable system.


Affected software

Oniguruma
Amazon Linux AMI
Gentoo Linux
SUSE CaaS Platform
SUSE Manager Server
SUSE Manager Retail Branch Server
SUSE Manager Proxy
SUSE Linux Enterprise Micro
openSUSE Leap Micro
SUSE Enterprise Storage
SUSE Linux Enterprise Storage
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for ARM 64
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for x86_64
Anolis OS
Red Hat CodeReady Linux Builder for Power, little endian
Red Hat CodeReady Linux Builder for ARM 64
Red Hat CodeReady Linux Builder for x86_64
Red Hat CodeReady Linux Builder for IBM z Systems
Red Hat Enterprise Linux Server - AUS
Red Hat Enterprise Linux for x86_64 - Extended Update Support
Red Hat Enterprise Linux for IBM z Systems - Extended Update Support
Red Hat Enterprise Linux for Power, little endian - Extended Update Support
Red Hat Enterprise Linux Server - TUS
Red Hat Enterprise Linux for ARM 64 - Extended Update Support
Red Hat CodeReady Linux Builder for x86_64 - Extended Update Support
Red Hat CodeReady Linux Builder for Power, little endian - Extended Update Support
SUSE Linux Enterprise Server for SAP
SUSE Linux Enterprise Server
SUSE Linux Enterprise High Performance Computing
SUSE Linux Enterprise Desktop
SUSE Linux Enterprise Module for Basesystem
SUSE Linux Enterprise Server for SAP Applications
openSUSE Leap
Fedora
Migration Toolkit for Containers
Cloud Pak for Network Automation
PowerStore T
QRadar Assistant
DB2 on Cloud Pak for Data
DB2 Warehouse on Cloud Pak for Data
Robotic Process Automation for Cloud Pak
Red Hat Advanced Cluster Security for Kubernetes
IBM Cloud Transformation Advisor
php7 (Alpine package)
Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions
oniguruma-devel
oniguruma-debugsource
libonig4-debuginfo
libonig4
oniguruma (Red Hat package)
oniguruma
oniguruma-doc
Juniper Secure Analytics (JSA)
Red Hat OpenShift GitOps
Dell EMC VxRail Appliance
IBM Qradar SIEM

How to mitigate CVE-2019-13224

Install updates from vendor's website.

Oniguruma - update to 6.9.3
Migration Toolkit for Containers - addressed in versions 1.7.15, 1.8.3
Cloud Pak for Network Automation - update to 2.7.2
Red Hat Advanced Cluster Security for Kubernetes - addressed in versions 4.3.5, 4.4.0
php7 (Alpine package) - update to 7.1.32-r0
Juniper Secure Analytics (JSA) - update to 7.5.0 UP8 IF03
Red Hat OpenShift GitOps - addressed in versions 1.10.0, 1.11
PowerStore T - update to 3.5.0.1-2083289
QRadar Assistant - update to 3.8.1
IBM Cloud Transformation Advisor - update to 3.10.0
DB2 on Cloud Pak for Data - update to 4.8.5
DB2 Warehouse on Cloud Pak for Data - update to 4.8.5
oniguruma-devel - update to 6.7.0-150000.3.3.1
oniguruma-debugsource - update to 6.7.0-150000.3.3.1
libonig4-debuginfo - update to 6.7.0-150000.3.3.1
libonig4 - update to 6.7.0-150000.3.3.1
oniguruma (Red Hat package) - addressed in versions 6.8.2-2.1.el8_6, 6.8.2-2.1.el8_8, 6.8.2-2.1.el8_9
oniguruma - update to 6.8.2-3.0.1
oniguruma-devel - update to 6.8.2-3.0.1
oniguruma-doc - update to 6.8.2-3.0.1
oniguruma - addressed in versions 6.9.1-2.fc29, 6.9.2-2.fc30
Dell EMC VxRail Appliance - addressed in versions 7.0.401, 8.0.000
IBM Qradar SIEM - update to 7.5.0 Update Pack 8 IF01
Robotic Process Automation for Cloud Pak - update to 21.0.6

External References

Related Security Bulletins