Integer overflow in Oniguruma - CVE-2019-19012
Published: November 18, 2019 / Updated: November 29, 2019
Vulnerability details
The vulnerability allows a remote attacker to compromise the target system.
The vulnerability exists due to integer overflow in the "search_in_range" function in "regexec.c". A remote attacker can use a specially crafted regular expression, trigger out-of-bounds read and cause a denial-of-service or information disclosure on the target system.
Affected software
Migration Toolkit for Containers
Cloud Pak for Network Automation
QRadar Assistant
DB2 on Cloud Pak for Data
DB2 Warehouse on Cloud Pak for Data
Robotic Process Automation for Cloud Pak
Red Hat Advanced Cluster Security for Kubernetes
IBM Cloud Transformation Advisor
Juniper Secure Analytics (JSA)
Anolis OS
Red Hat CodeReady Linux Builder for ARM 64
Red Hat CodeReady Linux Builder for Power, little endian
Red Hat CodeReady Linux Builder for x86_64
Red Hat CodeReady Linux Builder for IBM z Systems
Red Hat Enterprise Linux for x86_64 - Extended Update Support
Red Hat Enterprise Linux Server - AUS
Red Hat Enterprise Linux for IBM z Systems - Extended Update Support
Red Hat Enterprise Linux for Power, little endian - Extended Update Support
Red Hat Enterprise Linux Server - TUS
Red Hat Enterprise Linux for ARM 64 - Extended Update Support
Red Hat CodeReady Linux Builder for x86_64 - Extended Update Support
Red Hat CodeReady Linux Builder for Power, little endian - Extended Update Support
Ubuntu
Fedora
Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions
rubygem-net-telnet
rubygem-abrt-doc
rubygem-abrt
rubygem-xmlrpc
rubygem-io-console
rubygem-mysql2-doc
rubygem-mysql2
rubygem-pg
rubygem-pg-doc
rubygem-power_assert
rubygem-did_you_mean
rubygem-bigdecimal
rubygem-bundler-doc
rubygem-bundler
rubygem-json
rubygem-openssl
rubygem-mongo-doc
rubygem-mongo
ruby-irb
ruby-libs
ruby-doc
ruby-devel
ruby
rubygems
rubygems-devel
rubygem-psych
rubygem-test-unit
rubygem-bson-doc
rubygem-bson
libonig2 (Ubuntu package)
rubygem-minitest
rubygem-rdoc
oniguruma (Red Hat package)
oniguruma
oniguruma-devel
oniguruma-doc
rubygem-rake
Red Hat OpenShift GitOps
IBM Qradar SIEM
How to mitigate CVE-2019-19012
Migration Toolkit for Containers - addressed in versions 1.7.15, 1.8.3
Cloud Pak for Network Automation - update to 2.7.2
Red Hat Advanced Cluster Security for Kubernetes - addressed in versions 4.3.5, 4.4.0
Juniper Secure Analytics (JSA) - update to 7.5.0 UP8 IF03
rubygem-net-telnet - update to 0.1.1-114.0.1
rubygem-abrt-doc - update to 0.3.0-4
rubygem-abrt - update to 0.3.0-4
rubygem-xmlrpc - update to 0.3.0-114.0.1
rubygem-io-console - update to 0.4.6-114.0.1
rubygem-mysql2-doc - update to 0.4.10-4
rubygem-mysql2 - update to 0.4.10-4
rubygem-pg - update to 1.0.0-3.0.1
rubygem-pg-doc - update to 1.0.0-3.0.1
rubygem-power_assert - update to 1.1.1-114.0.1
rubygem-did_you_mean - update to 1.2.0-114.0.1
rubygem-bigdecimal - update to 1.3.4-114.0.1
Red Hat OpenShift GitOps - addressed in versions 1.10.0, 1.11
rubygem-bundler-doc - update to 1.16.1-5
rubygem-bundler - update to 1.16.1-5
rubygem-json - update to 2.1.0-114.0.1
rubygem-openssl - update to 2.1.2-114.0.1
rubygem-mongo-doc - update to 2.5.1-2
rubygem-mongo - update to 2.5.1-2
ruby-irb - update to 2.5.9-114.0.1
ruby-libs - update to 2.5.9-114.0.1
ruby-doc - update to 2.5.9-114.0.1
ruby-devel - update to 2.5.9-114.0.1
ruby - update to 2.5.9-114.0.1
rubygems - update to 2.7.6.3-114.0.1
rubygems-devel - update to 2.7.6.3-114.0.1
rubygem-psych - update to 3.0.2-114.0.1
rubygem-test-unit - update to 3.2.7-114.0.1
QRadar Assistant - update to 3.8.1
IBM Cloud Transformation Advisor - update to 3.10.0
rubygem-bson-doc - update to 4.3.0-2
rubygem-bson - update to 4.3.0-2
DB2 on Cloud Pak for Data - update to 4.8.5
DB2 Warehouse on Cloud Pak for Data - update to 4.8.5
libonig2 (Ubuntu package) - update to 5.9.1-1ubuntu1.1+esm2
rubygem-minitest - update to 5.10.3-114.0.1
rubygem-rdoc - update to 6.0.1.1-114.0.1
oniguruma (Red Hat package) - addressed in versions 6.8.2-2.1.el8_6, 6.8.2-2.1.el8_8, 6.8.2-2.1.el8_9
oniguruma - update to 6.8.2-3.0.1
oniguruma-devel - update to 6.8.2-3.0.1
oniguruma-doc - update to 6.8.2-3.0.1
oniguruma - addressed in versions 6.9.2-4.fc30, 6.9.4-1.fc31
IBM Qradar SIEM - update to 7.5.0 Update Pack 8 IF01
rubygem-rake - update to 12.3.3-114.0.1
Robotic Process Automation for Cloud Pak - update to 21.0.6
External References
Related Security Bulletins
- Multiple vulnerabilities in Oniguruma
- Multiple vulnerabilities in IBM Robotic Process Automation for Cloud Pak
- Red Hat Enterprise Linux 8.6 Extended Update Support update for oniguruma
- Red Hat Enterprise Linux 8.8 Extended Update Support update for oniguruma
- Red Hat Enterprise Linux 8 update for oniguruma
- Multiple vulnerabilities in Red Hat OpenShift GitOps
- Multiple vulnerabilities in Red Hat OpenShift GitOps
- Multiple vulnerabilities in Red Hat Advanced Cluster Security for Kubernetes 4.3
- Multiple vulnerabilities in Red Hat Advanced Cluster Security for Kubernetes 4.4
- Multiple vulnerabilities in IBM QRadar SIEM
- Multiple vulnerabilities in Red Hat Migration Toolkit for Containers (MTC) 1.8
- Multiple vulnerabilities in Red Hat Migration Toolkit for Containers (MTC) 1.7
- Multiple vulnerabilities in IBM Cloud Pak for Network Automation
- Multiple vulnerabilities in IBM Db2 on Cloud Pak for Data, and Db2 Warehouse on Cloud Pak for Data
- Multiple vulnerabilities in Juniper Secure Analytics (JSA)
- Multiple vulnerabilities in IBM Cloud Transformation Advisor
- Multiple vulnerabilities in IBM QRadar Assistant
- Anolis OS update for oniguruma
- Ubuntu update for libonig
- Fedora 30 update for oniguruma
- Fedora 31 update for oniguruma
- Anolis OS update for ruby:2.5 module