CVE-2019-9192
Summary
| CVE | CVE-2019-9192 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2019-02-26 18:29:00 UTC |
| Updated | 2023-11-07 03:13:00 UTC |
| Description | ** DISPUTED ** In the GNU C Library (aka glibc or libc6) through 2.29, check_dst_limits_calc_pos_1 in posix/regexec.c has Uncontrolled Recursion, as demonstrated by '(|)(\\1\\1)*' in grep, a different issue than CVE-2018-20796. NOTE: the software maintainer disputes that this is a vulnerability because the behavior occurs only with a crafted pattern. |
Risk And Classification
Problem Types: CWE-674
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| 24269 – (CVE-2018-20796) regexec: Infinite recursion in check_dst_limits_calc_pos_1 | MISC | sourceware.org | Exploit, Issue Tracking, Third Party Advisory |
| myF5 | support.f5.com | ||
| support.f5.com/csp/article/K26346590 | CONFIRM | support.f5.com | |
| CONFIRM:https://support.f5.com/csp/article/K26346590?utm_source=f5support&utm_medium=RSS | MITRE | support.f5.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.