CVE-2019-19246 describes a heap-based buffer over-read vulnerability in Oniguruma versions up to 6.9.3, specifically within the str_lower_case_match function in regexec.c. This flaw impacts products utilizing Oniguruma, including PHP 7.3.x, Canonical, Debian, and Fedora Project. Rated 7.5 HIGH, the vulnerability is network-exploitable with low attack complexity, requiring no user interaction or privileges, and can lead to a denial of service. There is currently no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion or media coverage surrounding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 6.9.3CPE matchmatch criteria | cpe:2.3:a:oniguruma_project:oniguruma:*:*:*:*:*:*:*:* | ||
>= 7.3.0, < 7.3.10CPE matchmatch criteria | cpe:2.3:a:php:php:*:*:*:*:*:*:*:* | ||
31CPE matchmatch criteria | cpe:2.3:o:fedoraproject:fedora:31:*:*:*:*:*:*:* | ||
14.04CPE matchmatch criteria | cpe:2.3:o:canonical:ubuntu_linux:14.04:*:*:*:esm:*:*:* | ||
8.0CPE matchmatch criteria | cpe:2.3:o:debian:debian_linux:8.0:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.