Resource exhaustion in Oniguruma - CVE-2019-16163
Published: September 9, 2019 / Updated: July 17, 2020
Vulnerability identifier: #VU30789
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2019-16163
CWE-ID: CWE-400
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote non-authenticated attacker to perform a denial of service (DoS) attack.
Oniguruma before 6.9.3 allows Stack Exhaustion in regcomp.c because of recursion in regparse.c.
Affected software
Oniguruma
Voice Gateway
Migration Toolkit for Containers
Cloud Pak for Network Automation
PowerStore T
QRadar Assistant
DB2 Warehouse on Cloud Pak for Data
DB2 on Cloud Pak for Data
Robotic Process Automation for Cloud Pak
Red Hat Advanced Cluster Security for Kubernetes
IBM Cloud Pak for Security
SUSE CaaS Platform
SUSE Manager Proxy
SUSE Manager Retail Branch Server
SUSE Manager Server
SUSE Linux Enterprise Micro
openSUSE Leap Micro
SUSE Enterprise Storage
SUSE Linux Enterprise Storage
Red Hat Enterprise Linux for x86_64
Red Hat Enterprise Linux for IBM z Systems
Red Hat CodeReady Linux Builder for x86_64
Red Hat Enterprise Linux for Power, little endian
Red Hat CodeReady Linux Builder for Power, little endian
Anolis OS
Red Hat Enterprise Linux for ARM 64
Red Hat CodeReady Linux Builder for IBM z Systems
Red Hat CodeReady Linux Builder for ARM 64
Red Hat Enterprise Linux Server - TUS
Red Hat Enterprise Linux for ARM 64 - Extended Update Support
Red Hat Enterprise Linux for Power, little endian - Extended Update Support
Red Hat Enterprise Linux for IBM z Systems - Extended Update Support
Red Hat Enterprise Linux Server - AUS
Red Hat Enterprise Linux for x86_64 - Extended Update Support
Red Hat CodeReady Linux Builder for Power, little endian - Extended Update Support
Red Hat CodeReady Linux Builder for x86_64 - Extended Update Support
Ubuntu
SUSE Linux Enterprise Server for SAP
SUSE Linux Enterprise Server
SUSE Linux Enterprise High Performance Computing
SUSE Linux Enterprise Server for SAP Applications
SUSE Linux Enterprise Desktop
SUSE Linux Enterprise Module for Basesystem
openSUSE Leap
Fedora
Juniper Secure Analytics (JSA)
Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions
libonig2 (Ubuntu package)
libonig4-debuginfo
oniguruma-devel
oniguruma-debugsource
libonig4
oniguruma (Red Hat package)
oniguruma
oniguruma-doc
Red Hat OpenShift GitOps
Dell EMC VxRail Appliance
IBM Qradar SIEM
Voice Gateway
Migration Toolkit for Containers
Cloud Pak for Network Automation
PowerStore T
QRadar Assistant
DB2 Warehouse on Cloud Pak for Data
DB2 on Cloud Pak for Data
Robotic Process Automation for Cloud Pak
Red Hat Advanced Cluster Security for Kubernetes
IBM Cloud Pak for Security
SUSE CaaS Platform
SUSE Manager Proxy
SUSE Manager Retail Branch Server
SUSE Manager Server
SUSE Linux Enterprise Micro
openSUSE Leap Micro
SUSE Enterprise Storage
SUSE Linux Enterprise Storage
Red Hat Enterprise Linux for x86_64
Red Hat Enterprise Linux for IBM z Systems
Red Hat CodeReady Linux Builder for x86_64
Red Hat Enterprise Linux for Power, little endian
Red Hat CodeReady Linux Builder for Power, little endian
Anolis OS
Red Hat Enterprise Linux for ARM 64
Red Hat CodeReady Linux Builder for IBM z Systems
Red Hat CodeReady Linux Builder for ARM 64
Red Hat Enterprise Linux Server - TUS
Red Hat Enterprise Linux for ARM 64 - Extended Update Support
Red Hat Enterprise Linux for Power, little endian - Extended Update Support
Red Hat Enterprise Linux for IBM z Systems - Extended Update Support
Red Hat Enterprise Linux Server - AUS
Red Hat Enterprise Linux for x86_64 - Extended Update Support
Red Hat CodeReady Linux Builder for Power, little endian - Extended Update Support
Red Hat CodeReady Linux Builder for x86_64 - Extended Update Support
Ubuntu
SUSE Linux Enterprise Server for SAP
SUSE Linux Enterprise Server
SUSE Linux Enterprise High Performance Computing
SUSE Linux Enterprise Server for SAP Applications
SUSE Linux Enterprise Desktop
SUSE Linux Enterprise Module for Basesystem
openSUSE Leap
Fedora
Juniper Secure Analytics (JSA)
Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions
libonig2 (Ubuntu package)
libonig4-debuginfo
oniguruma-devel
oniguruma-debugsource
libonig4
oniguruma (Red Hat package)
oniguruma
oniguruma-doc
Red Hat OpenShift GitOps
Dell EMC VxRail Appliance
IBM Qradar SIEM
How to mitigate CVE-2019-16163
Install update from vendor's website.
Oniguruma - update to 6.9.3
Voice Gateway - update to 1.0.8.12
Migration Toolkit for Containers - addressed in versions 1.7.15, 1.8.3
Cloud Pak for Network Automation - update to 2.7.2
Red Hat Advanced Cluster Security for Kubernetes - addressed in versions 4.3.5, 4.4.0
Juniper Secure Analytics (JSA) - update to 7.5.0 UP8 IF03
Red Hat OpenShift GitOps - addressed in versions 1.10.0, 1.11
IBM Cloud Pak for Security - update to 1.11.2.0
PowerStore T - update to 3.5.0.1-2083289
QRadar Assistant - update to 3.8.1
DB2 Warehouse on Cloud Pak for Data - update to 4.8.5
DB2 on Cloud Pak for Data - update to 4.8.5
libonig2 (Ubuntu package) - update to 5.9.1-1ubuntu1.1+esm2
libonig4-debuginfo - update to 6.7.0-150000.3.3.1
oniguruma-devel - update to 6.7.0-150000.3.3.1
oniguruma-debugsource - update to 6.7.0-150000.3.3.1
libonig4 - update to 6.7.0-150000.3.3.1
oniguruma (Red Hat package) - addressed in versions 6.8.2-2.1.el8_6, 6.8.2-2.1.el8_8, 6.8.2-2.1.el8_9
oniguruma - update to 6.8.2-3.0.1
oniguruma-devel - update to 6.8.2-3.0.1
oniguruma-doc - update to 6.8.2-3.0.1
oniguruma - addressed in versions 6.9.1-3.fc29, 6.9.2-3.fc30
Dell EMC VxRail Appliance - addressed in versions 7.0.401, 8.0.000
IBM Qradar SIEM - update to 7.5.0 Update Pack 8 IF01
Robotic Process Automation for Cloud Pak - update to 21.0.6
Voice Gateway - update to 1.0.8.12
Migration Toolkit for Containers - addressed in versions 1.7.15, 1.8.3
Cloud Pak for Network Automation - update to 2.7.2
Red Hat Advanced Cluster Security for Kubernetes - addressed in versions 4.3.5, 4.4.0
Juniper Secure Analytics (JSA) - update to 7.5.0 UP8 IF03
Red Hat OpenShift GitOps - addressed in versions 1.10.0, 1.11
IBM Cloud Pak for Security - update to 1.11.2.0
PowerStore T - update to 3.5.0.1-2083289
QRadar Assistant - update to 3.8.1
DB2 Warehouse on Cloud Pak for Data - update to 4.8.5
DB2 on Cloud Pak for Data - update to 4.8.5
libonig2 (Ubuntu package) - update to 5.9.1-1ubuntu1.1+esm2
libonig4-debuginfo - update to 6.7.0-150000.3.3.1
oniguruma-devel - update to 6.7.0-150000.3.3.1
oniguruma-debugsource - update to 6.7.0-150000.3.3.1
libonig4 - update to 6.7.0-150000.3.3.1
oniguruma (Red Hat package) - addressed in versions 6.8.2-2.1.el8_6, 6.8.2-2.1.el8_8, 6.8.2-2.1.el8_9
oniguruma - update to 6.8.2-3.0.1
oniguruma-devel - update to 6.8.2-3.0.1
oniguruma-doc - update to 6.8.2-3.0.1
oniguruma - addressed in versions 6.9.1-3.fc29, 6.9.2-3.fc30
Dell EMC VxRail Appliance - addressed in versions 7.0.401, 8.0.000
IBM Qradar SIEM - update to 7.5.0 Update Pack 8 IF01
Robotic Process Automation for Cloud Pak - update to 21.0.6
External References
- https://github.com/kkos/oniguruma/commit/4097828d7cc87589864fecf452f2cd46c5f37180
- https://github.com/kkos/oniguruma/compare/v6.9.2...v6.9.3
- https://github.com/kkos/oniguruma/issues/147
- https://lists.debian.org/debian-lts-announce/2019/09/msg00010.html
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/NWOWZZNFSAWM3BUTQNAE3PD44A6JU4KE/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/ZW47MSFZ6WYOAOFXHBDGU4LYACFRKC2Y/
Related Security Bulletins
- Resource exhaustion in K.Kosako Oniguruma
- SUSE update for oniguruma
- Multiple vulnerabilities in Dell VxRail
- Multiple vulnerabilities in Dell VxRail Appliance components
- Multiple vulnerabilities in IBM Robotic Process Automation for Cloud Pak
- Multiple vulnerabilities in Dell PowerStore Family
- Red Hat Enterprise Linux 8.6 Extended Update Support update for oniguruma
- Red Hat Enterprise Linux 8.8 Extended Update Support update for oniguruma
- Red Hat Enterprise Linux 8 update for oniguruma
- Multiple vulnerabilities in Red Hat OpenShift GitOps
- Multiple vulnerabilities in Red Hat OpenShift GitOps
- Multiple vulnerabilities in Red Hat Advanced Cluster Security for Kubernetes 4.3
- Multiple vulnerabilities in Red Hat Advanced Cluster Security for Kubernetes 4.4
- Multiple vulnerabilities in IBM QRadar SIEM
- Multiple vulnerabilities in Red Hat Migration Toolkit for Containers (MTC) 1.8
- Multiple vulnerabilities in Red Hat Migration Toolkit for Containers (MTC) 1.7
- Multiple vulnerabilities in IBM Cloud Pak for Network Automation
- Multiple vulnerabilities in IBM Db2 on Cloud Pak for Data, and Db2 Warehouse on Cloud Pak for Data
- Multiple vulnerabilities in Juniper Secure Analytics (JSA)
- Multiple vulnerabilities in IBM QRadar Assistant
- Anolis OS update for oniguruma
- Multiple vulnerabilities in IBM Cloud Pak for Security
- Ubuntu update for libonig
- Red Hat Enterprise Linux 8 update for the php:7.3 module
- Fedora 30 update for oniguruma
- Fedora 29 update for oniguruma
- Multiple vulnerabilities in IBM Voice Gateway