CVE-2019-20838
Summary
| CVE | CVE-2019-20838 |
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2020-06-15 17:15:00 UTC |
| Updated | 2024-03-27 16:05:00 UTC |
| Description | libpcre in PCRE before 8.43 allows a subject buffer over-read in JIT when UTF is disabled, and \X or \R has more than one fixed quantifier, a related issue to CVE-2019-20454. |
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|
| Pony Mail! |
MLIST |
lists.apache.org |
Mailing List, Third Party Advisory |
| Full Disclosure: APPLE-SA-2021-02-01-1 macOS Big Sur 11.2, Security Update 2021-001 Catalina, Security Update 2021-001 Mojave |
FULLDISC |
seclists.org |
Mailing List, Third Party Advisory |
| Full Disclosure: APPLE-SA-2020-12-14-4 Additional information for APPLE-SA-2020-11-13-1 macOS Big Sur 11.0.1 |
FULLDISC |
seclists.org |
Mailing List, Third Party Advisory |
| About the security content of macOS Big Sur 11.0.1 - Apple Support |
CONFIRM |
support.apple.com |
Vendor Advisory |
| About the security content of macOS Big Sur 11.2, Security Update 2021-001 Catalina, Security Update 2021-001 Mojave - Apple Support |
CONFIRM |
support.apple.com |
Vendor Advisory |
| www.pcre.org/original/changelog.txt |
MISC |
www.pcre.org |
Release Notes, Vendor Advisory |
| 717920 – (CVE-2019-20838, CVE-2020-14155) <dev-libs/libpcre-8.44: Multiple vulnerabilities (CVE-2019-20838, CVE-2020-14155) |
MISC |
bugs.gentoo.org |
Issue Tracking, Patch, Third Party Advisory, VDB Entry |
| [mina-dev] 20210225 [jira] [Created] (FTPSERVER-500) Security vulnerability in common/lib/log4j-1.2.17.jar |
|
lists.apache.org |
|
| CVE Program record |
CVE.ORG |
www.cve.org |
canonical |
| NVD vulnerability detail |
NVD |
nvd.nist.gov |
canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 159497 Oracle Enterprise Linux Security Update for pcre (ELSA-2021-4373)
- 198789 Ubuntu Security Notification for PCRE Vulnerabilities (USN-5425-1)
- 239835 Red Hat Update for pcre (RHSA-2021:4373)
- 239865 Red Hat Update for red hat jboss core services apache Hypertext Transfer Protocol (HTTP) server 2.4.37 sp10 (RHSA-2021:4614)
- 378883 Splunk Enterprise August Third Party Package Updates (SVD-2023-0808)
- 751288 OpenSUSE Security Update for pcre (openSUSE-SU-2021:3529-1)
- 751317 OpenSUSE Security Update for pcre (openSUSE-SU-2021:1441-1)
- 751361 SUSE Enterprise Linux Security Update for pcre (SUSE-SU-2021:3652-1)
- 900129 CBL-Mariner Linux Security Update for pcre 8.42
- 903163 Common Base Linux Mariner (CBL-Mariner) Security Update for pcre (1821)
- 940117 AlmaLinux Security Update for pcre (ALSA-2021:4373)
- 960410 Rocky Linux Security Update for pcre (RLSA-2021:4373)