#VU22932 Buffer Over-read in Oniguruma - CVE-2019-19203
Published: November 22, 2019 / Updated: November 29, 2019
Oniguruma
K.Kosako
Description
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists in the "gb18030_mbc_enc_len" function in "gb18030.c" file due to the UChar pointer is dereferenced without checking if it passed the end of the matched string. A remote attacker can cause a denial of service condition on the target system.