Out-of-Bounds Read in PCRE Affects Multiple Applications
CVE-2019-20454
5.1MEDIUM
What is CVE-2019-20454?
An out-of-bounds read vulnerability exists in PCRE versions prior to 10.34, which can be triggered when the pattern \X is JIT compiled with specially crafted subjects in non-UTF mode. This issue could enable attackers to cause application crashes by parsing untrusted input, posing significant risks for applications reliant on PCRE for text pattern matching. The vulnerability arises in the do_extuni_no_utf function within the pcre2_jit_compile.c file.
References
CVSS V3.1
Score:
5.1
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Local
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
CVSS V3.0
Score:
5.1
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Local
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
