Oniguruma CVE-2017-9228 Out of Bounds Write Memory Corruption Vulnerability
BID:100320
Info
Oniguruma CVE-2017-9228 Out of Bounds Write Memory Corruption Vulnerability
| Bugtraq ID: | 100320 |
| Class: | Boundary Condition Error |
| CVE: |
CVE-2017-9228 |
| Remote: | Yes |
| Local: | No |
| Published: | May 23 2017 12:00AM |
| Updated: | May 23 2017 12:00AM |
| Credit: | lxxxxfdh |
| Vulnerable: |
Redhat Enterprise Linux 7 Redhat Enterprise Linux 6 Redhat Enterprise Linux 5 Redhat Collections for Red Hat Enterprise Linux 0 PHP PHP 7.1.5 PHP PHP 7.1.4 PHP PHP 7.1.1 PHP PHP 7.1.3 PHP PHP 7.1.2 kkos oniguruma 6.2 |
| Not Vulnerable: |
PHP PHP 7.1.7 PHP PHP 5.6.31 |
Discussion
Oniguruma CVE-2017-9228 Out of Bounds Write Memory Corruption Vulnerability
Oniguruma is prone to a memory-corruption.
Attackers can exploit this issue to crash the application, resulting in a denial-of-service condition. Due to the nature of this issue, arbitrary code execution may be possible but this has not been confirmed.
Oniguruma 6.2.0 is vulnerable; prior versions may also be affected.
Oniguruma is prone to a memory-corruption.
Attackers can exploit this issue to crash the application, resulting in a denial-of-service condition. Due to the nature of this issue, arbitrary code execution may be possible but this has not been confirmed.
Oniguruma 6.2.0 is vulnerable; prior versions may also be affected.
Exploit / POC
Oniguruma CVE-2017-9228 Out of Bounds Write Memory Corruption Vulnerability
Currently, we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Currently, we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution / Fix
Oniguruma CVE-2017-9228 Out of Bounds Write Memory Corruption Vulnerability
Solution:
Updates are available. Please see the references or vendor advisory for more information.
Solution:
Updates are available. Please see the references or vendor advisory for more information.
References
Oniguruma CVE-2017-9228 Out of Bounds Write Memory Corruption Vulnerability
References:
References:
- Bug 1466740 - (CVE-2017-9228) CVE-2017-9228 oniguruma: Out-of-bounds heap write (Red Hat)
- CVE-2017-9228 (Red Hat)
- fix #60 : invalid state(CCS_VALUE) in parse_char_class() (kkos)
- Heap corruption in next_state_val() due to uninitialized local variable #60 (kkos)
- PHP 5 ChangeLog (PHP)
- PHP 7 ChangeLog (PHP)