Out-of-bounds read in PCRE - CVE-2019-20838
Published: June 15, 2020 / Updated: October 2, 2024
Vulnerability identifier: #VU30256
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2019-20838
CWE-ID: CWE-125
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote non-authenticated attacker to perform a denial of service (DoS) attack.
libpcre in PCRE before 8.43 allows a subject buffer over-read in JIT when UTF is disabled, and X or R has more than one fixed quantifier, a related issue to CVE-2019-20454.
Affected software
PCRE
jbcs-httpd24-openssl-pkcs11 (Red Hat package)
jbcs-httpd24-openssl-chil (Red Hat package)
jbcs-httpd24-apr-util (Red Hat package)
jbcs-httpd24-apr (Red Hat package)
jbcs-httpd24-mod_http2 (Red Hat package)
jbcs-httpd24-nghttp2 (Red Hat package)
jbcs-httpd24-mod_md (Red Hat package)
jbcs-httpd24-httpd (Red Hat package)
jbcs-httpd24-mod_security (Red Hat package)
jbcs-httpd24-curl (Red Hat package)
libpcre3 (Ubuntu package)
pcre (Red Hat package)
libpcre1
pcre-devel-static
libpcrecpp0-debuginfo-32bit
libpcrecpp0-32bit
pcre-devel
pcre-debugsource
libpcreposix0-debuginfo
libpcreposix0
libpcrecpp0-debuginfo
libpcrecpp0
libpcre16-0-debuginfo
libpcre16-0
libpcre1-debuginfo
libpcre1-debuginfo-32bit
libpcre1-32bit
pcre-tools
pcre-tools-debuginfo
libpcrecpp0-32bit-debuginfo
libpcre1-32bit-debuginfo
selinux-policy-minimum
selinux-policy-devel
selinux-policy
TensorFlow
Ansible Automation Platform
Dell Secure Connect Gateway
Red Hat Advanced Cluster Management for Kubernetes
Red Hat Advanced Cluster Security for Kubernetes
Red Hat OpenStack
Migration Toolkit for Containers
Red Hat OpenShift Container Platform
Cloud Pak for Security (CP4S)
JBoss Core Services
SUSE MicroOS
Red Hat CodeReady Linux Builder for Power, little endian
HPE Helion Openstack
Red Hat Enterprise Linux for x86_64
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for ARM 64
Red Hat CodeReady Linux Builder for x86_64
Red Hat CodeReady Linux Builder for ARM 64
Red Hat CodeReady Linux Builder for IBM z Systems
SUSE OpenStack Cloud Crowbar
SUSE OpenStack Cloud
macOS
SUSE Linux Enterprise Server
SUSE Linux Enterprise Server for SAP
SUSE Linux Enterprise High Availability
SUSE Linux Enterprise Workstation Extension
SUSE Linux Enterprise Software Development Kit
Ubuntu
SUSE Linux Enterprise Module for Basesystem
Splunk Enterprise
cflinuxfs3
IBM Aspera Shares
IBM Aspera Console
Red Hat OpenShift Serverless
OpenShift Virtualization
IBM Aspera Faspex for Windows
IBM Aspera Faspex for Linux
jbcs-httpd24-openssl-pkcs11 (Red Hat package)
jbcs-httpd24-openssl-chil (Red Hat package)
jbcs-httpd24-apr-util (Red Hat package)
jbcs-httpd24-apr (Red Hat package)
jbcs-httpd24-mod_http2 (Red Hat package)
jbcs-httpd24-nghttp2 (Red Hat package)
jbcs-httpd24-mod_md (Red Hat package)
jbcs-httpd24-httpd (Red Hat package)
jbcs-httpd24-mod_security (Red Hat package)
jbcs-httpd24-curl (Red Hat package)
libpcre3 (Ubuntu package)
pcre (Red Hat package)
libpcre1
pcre-devel-static
libpcrecpp0-debuginfo-32bit
libpcrecpp0-32bit
pcre-devel
pcre-debugsource
libpcreposix0-debuginfo
libpcreposix0
libpcrecpp0-debuginfo
libpcrecpp0
libpcre16-0-debuginfo
libpcre16-0
libpcre1-debuginfo
libpcre1-debuginfo-32bit
libpcre1-32bit
pcre-tools
pcre-tools-debuginfo
libpcrecpp0-32bit-debuginfo
libpcre1-32bit-debuginfo
selinux-policy-minimum
selinux-policy-devel
selinux-policy
TensorFlow
Ansible Automation Platform
Dell Secure Connect Gateway
Red Hat Advanced Cluster Management for Kubernetes
Red Hat Advanced Cluster Security for Kubernetes
Red Hat OpenStack
Migration Toolkit for Containers
Red Hat OpenShift Container Platform
Cloud Pak for Security (CP4S)
JBoss Core Services
SUSE MicroOS
Red Hat CodeReady Linux Builder for Power, little endian
HPE Helion Openstack
Red Hat Enterprise Linux for x86_64
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for ARM 64
Red Hat CodeReady Linux Builder for x86_64
Red Hat CodeReady Linux Builder for ARM 64
Red Hat CodeReady Linux Builder for IBM z Systems
SUSE OpenStack Cloud Crowbar
SUSE OpenStack Cloud
macOS
SUSE Linux Enterprise Server
SUSE Linux Enterprise Server for SAP
SUSE Linux Enterprise High Availability
SUSE Linux Enterprise Workstation Extension
SUSE Linux Enterprise Software Development Kit
Ubuntu
SUSE Linux Enterprise Module for Basesystem
Splunk Enterprise
cflinuxfs3
IBM Aspera Shares
IBM Aspera Console
Red Hat OpenShift Serverless
OpenShift Virtualization
IBM Aspera Faspex for Windows
IBM Aspera Faspex for Linux
How to mitigate CVE-2019-20838
Install update from vendor's website.
PCRE - update to 8.43
jbcs-httpd24-openssl-pkcs11 (Red Hat package) - addressed in versions 0.4.10-22.el8jbcs, 0.4.10-22.jbcs.el7
TensorFlow - addressed in versions 1.15.5, 2.0.4, 2.1.3, 2.2.2, 2.3.2
jbcs-httpd24-openssl-chil (Red Hat package) - addressed in versions 1.0.0-7.el8jbcs, 1.0.0-7.jbcs.el7
jbcs-httpd24-apr-util (Red Hat package) - addressed in versions 1.6.1-84.el8jbcs, 1.6.1-84.jbcs.el7
jbcs-httpd24-apr (Red Hat package) - addressed in versions 1.6.3-107.el8jbcs, 1.6.3-107.jbcs.el7
Migration Toolkit for Containers - addressed in versions 1.5.4, 1.7.3, 1.7.4
Cloud Pak for Security (CP4S) - update to 1.10.7.0
jbcs-httpd24-mod_http2 (Red Hat package) - addressed in versions 1.15.7-21.el8jbcs, 1.15.7-21.jbcs.el7
jbcs-httpd24-nghttp2 (Red Hat package) - addressed in versions 1.39.2-39.el8jbcs, 1.39.2-39.jbcs.el7
jbcs-httpd24-mod_md (Red Hat package) - addressed in versions 2.0.8-40.el8jbcs, 2.0.8-40.jbcs.el7
JBoss Core Services - update to 2.4.37 SP10
jbcs-httpd24-httpd (Red Hat package) - addressed in versions 2.4.37-78.el8jbcs, 2.4.37-78.jbcs.el7
jbcs-httpd24-mod_security (Red Hat package) - addressed in versions 2.9.2-67.GA.el8jbcs, 2.9.2-67.GA.jbcs.el7
Red Hat OpenShift Container Platform - addressed in versions 4.11.0, 4.11.45
Dell Secure Connect Gateway - update to 5.12.00.10
jbcs-httpd24-curl (Red Hat package) - addressed in versions 7.78.0-2.el8jbcs, 7.78.0-2.jbcs.el7
Splunk Enterprise - addressed in versions 8.2.12, 9.0.6, 9.1.1
macOS - update to 11.2 20D64
cflinuxfs3 - update to 0.299.0
IBM Aspera Shares - update to 1.10.0 PL4
Red Hat OpenShift Serverless - update to 1.20.0
Red Hat Advanced Cluster Management for Kubernetes - update to 2.2.10
IBM Aspera Console - update to 3.4.2 PL 10
Red Hat Advanced Cluster Security for Kubernetes - update to 3.67
IBM Aspera Faspex for Windows - update to 4.4.2
IBM Aspera Faspex for Linux - update to 4.4.2
OpenShift Virtualization - update to 4.11.0
libpcre3 (Ubuntu package) - addressed in versions 2:8.39-9ubuntu0.1, 2:8.39-12ubuntu0.1, 2:8.39-13ubuntu0.21.10.1, 2:8.39-13ubuntu0.22.04.1
pcre (Red Hat package) - update to 8.42-6.el8
libpcre1 - addressed in versions 8.45-8.7.1, 8.45-20.10.1
pcre-devel-static - update to 8.45-8.7.1
libpcrecpp0-debuginfo-32bit - update to 8.45-8.7.1
libpcrecpp0-32bit - addressed in versions 8.45-8.7.1, 8.45-20.10.1
pcre-devel - addressed in versions 8.45-8.7.1, 8.45-20.10.1
pcre-debugsource - addressed in versions 8.45-8.7.1, 8.45-20.10.1
libpcreposix0-debuginfo - addressed in versions 8.45-8.7.1, 8.45-20.10.1
libpcreposix0 - addressed in versions 8.45-8.7.1, 8.45-20.10.1
libpcrecpp0-debuginfo - addressed in versions 8.45-8.7.1, 8.45-20.10.1
libpcrecpp0 - addressed in versions 8.45-8.7.1, 8.45-20.10.1
libpcre16-0-debuginfo - addressed in versions 8.45-8.7.1, 8.45-20.10.1
libpcre16-0 - addressed in versions 8.45-8.7.1, 8.45-20.10.1
libpcre1-debuginfo - addressed in versions 8.45-8.7.1, 8.45-20.10.1
libpcre1-debuginfo-32bit - update to 8.45-8.7.1
libpcre1-32bit - addressed in versions 8.45-8.7.1, 8.45-20.10.1
pcre-tools - addressed in versions 8.45-8.7.1, 8.45-20.10.1
pcre-tools-debuginfo - addressed in versions 8.45-8.7.1, 8.45-20.10.1
libpcrecpp0-32bit-debuginfo - update to 8.45-20.10.1
libpcre1-32bit-debuginfo - update to 8.45-20.10.1
Red Hat OpenStack - update to 16.2
selinux-policy-minimum - update to 20140730-36.5.2
selinux-policy-devel - update to 20140730-36.5.2
selinux-policy - update to 20140730-36.5.2
jbcs-httpd24-openssl-pkcs11 (Red Hat package) - addressed in versions 0.4.10-22.el8jbcs, 0.4.10-22.jbcs.el7
TensorFlow - addressed in versions 1.15.5, 2.0.4, 2.1.3, 2.2.2, 2.3.2
jbcs-httpd24-openssl-chil (Red Hat package) - addressed in versions 1.0.0-7.el8jbcs, 1.0.0-7.jbcs.el7
jbcs-httpd24-apr-util (Red Hat package) - addressed in versions 1.6.1-84.el8jbcs, 1.6.1-84.jbcs.el7
jbcs-httpd24-apr (Red Hat package) - addressed in versions 1.6.3-107.el8jbcs, 1.6.3-107.jbcs.el7
Migration Toolkit for Containers - addressed in versions 1.5.4, 1.7.3, 1.7.4
Cloud Pak for Security (CP4S) - update to 1.10.7.0
jbcs-httpd24-mod_http2 (Red Hat package) - addressed in versions 1.15.7-21.el8jbcs, 1.15.7-21.jbcs.el7
jbcs-httpd24-nghttp2 (Red Hat package) - addressed in versions 1.39.2-39.el8jbcs, 1.39.2-39.jbcs.el7
jbcs-httpd24-mod_md (Red Hat package) - addressed in versions 2.0.8-40.el8jbcs, 2.0.8-40.jbcs.el7
JBoss Core Services - update to 2.4.37 SP10
jbcs-httpd24-httpd (Red Hat package) - addressed in versions 2.4.37-78.el8jbcs, 2.4.37-78.jbcs.el7
jbcs-httpd24-mod_security (Red Hat package) - addressed in versions 2.9.2-67.GA.el8jbcs, 2.9.2-67.GA.jbcs.el7
Red Hat OpenShift Container Platform - addressed in versions 4.11.0, 4.11.45
Dell Secure Connect Gateway - update to 5.12.00.10
jbcs-httpd24-curl (Red Hat package) - addressed in versions 7.78.0-2.el8jbcs, 7.78.0-2.jbcs.el7
Splunk Enterprise - addressed in versions 8.2.12, 9.0.6, 9.1.1
macOS - update to 11.2 20D64
cflinuxfs3 - update to 0.299.0
IBM Aspera Shares - update to 1.10.0 PL4
Red Hat OpenShift Serverless - update to 1.20.0
Red Hat Advanced Cluster Management for Kubernetes - update to 2.2.10
IBM Aspera Console - update to 3.4.2 PL 10
Red Hat Advanced Cluster Security for Kubernetes - update to 3.67
IBM Aspera Faspex for Windows - update to 4.4.2
IBM Aspera Faspex for Linux - update to 4.4.2
OpenShift Virtualization - update to 4.11.0
libpcre3 (Ubuntu package) - addressed in versions 2:8.39-9ubuntu0.1, 2:8.39-12ubuntu0.1, 2:8.39-13ubuntu0.21.10.1, 2:8.39-13ubuntu0.22.04.1
pcre (Red Hat package) - update to 8.42-6.el8
libpcre1 - addressed in versions 8.45-8.7.1, 8.45-20.10.1
pcre-devel-static - update to 8.45-8.7.1
libpcrecpp0-debuginfo-32bit - update to 8.45-8.7.1
libpcrecpp0-32bit - addressed in versions 8.45-8.7.1, 8.45-20.10.1
pcre-devel - addressed in versions 8.45-8.7.1, 8.45-20.10.1
pcre-debugsource - addressed in versions 8.45-8.7.1, 8.45-20.10.1
libpcreposix0-debuginfo - addressed in versions 8.45-8.7.1, 8.45-20.10.1
libpcreposix0 - addressed in versions 8.45-8.7.1, 8.45-20.10.1
libpcrecpp0-debuginfo - addressed in versions 8.45-8.7.1, 8.45-20.10.1
libpcrecpp0 - addressed in versions 8.45-8.7.1, 8.45-20.10.1
libpcre16-0-debuginfo - addressed in versions 8.45-8.7.1, 8.45-20.10.1
libpcre16-0 - addressed in versions 8.45-8.7.1, 8.45-20.10.1
libpcre1-debuginfo - addressed in versions 8.45-8.7.1, 8.45-20.10.1
libpcre1-debuginfo-32bit - update to 8.45-8.7.1
libpcre1-32bit - addressed in versions 8.45-8.7.1, 8.45-20.10.1
pcre-tools - addressed in versions 8.45-8.7.1, 8.45-20.10.1
pcre-tools-debuginfo - addressed in versions 8.45-8.7.1, 8.45-20.10.1
libpcrecpp0-32bit-debuginfo - update to 8.45-20.10.1
libpcre1-32bit-debuginfo - update to 8.45-20.10.1
Red Hat OpenStack - update to 16.2
selinux-policy-minimum - update to 20140730-36.5.2
selinux-policy-devel - update to 20140730-36.5.2
selinux-policy - update to 20140730-36.5.2
External References
Related Security Bulletins
- Out-of-bounds read in PCRE PCRE
- Multiple vulnerabilities in TensorFlow
- Multiple vulnerabilities in Apple macOS
- Multiple vulnerabilities in Red Hat JBoss Core Services Apache HTTP Server
- Ubuntu update for pcre3
- Cloud Foundry Foundation cflinuxfs3 update for libpcre
- SUSE update for pcre
- Multiple vulnerabilities in DELL Secure Connect Gateway Security
- Multiple vulnerabilities in Migration Toolkit for Containers (MTC)
- Multiple vulnerabilities in OpenShift Container Platform 4.11
- Multiple vulnerabilities in OpenShift Container Platform 4.11
- Multiple vulnerabilities in Migration Toolkit for Containers (MTC) 1.7
- Multiple vulnerabilities in OpenShift Virtualization
- Multiple vulnerabilities in IBM Aspera Faspex
- Red Hat Enterprise Linux 8 update for pcre
- SUSE update for pcre
- Multiple vulnerabilities in OpenShift Container Platform 4.11
- Splunk Enterprise update for third-party packages
- Multiple vulnerabilities in IBM Cloud Pak for Security (CP4S)
- Multiple vulnerabilities in Red Hat Ansible Automation Platform 2.4
- Multiple vulnerabilities in IBM Aspera Console
- Multiple vulnerabilities in IBM Aspera Shares
- Multiple vulnerabilities in Red Hat Advanced Cluster Security for Kubernetes 3.67
- Multiple vulnerabilities in Red Hat OpenShift Serverless 1.20
- Multiple vulnerabilities in Red Hat OpenStack 16.2 packages
- Multiple vulnerabilities in Migration Toolkit for Containers 1.5
- Multiple vulnerabilities in Red Hat Advanced Cluster Management for Kubernetes 2.2