Oniguruma Multiple Memory Corruption Vulnerabilities
BID:101244
Info
Oniguruma Multiple Memory Corruption Vulnerabilities
| Bugtraq ID: | 101244 |
| Class: | Boundary Condition Error |
| CVE: |
CVE-2017-9226 CVE-2017-9224 |
| Remote: | Yes |
| Local: | No |
| Published: | May 22 2017 12:00AM |
| Updated: | May 22 2017 12:00AM |
| Credit: | lxxxxfdh |
| Vulnerable: |
RubyGems RubyGems 2.4.1 RubyGems RubyGems 2.4 Redhat Enterprise Linux 7 Redhat Enterprise Linux 6 Redhat Enterprise Linux 5 Redhat Collections for Red Hat Enterprise Linux 0 PHP PHP 7.1.5 PHP PHP 7.1.4 PHP PHP 7.1.1 PHP PHP 7.1 PHP PHP 7.1.3 PHP PHP 7.1.2 kkos oniguruma 6.2 IBM Flex System Manager 1.3.2 0 IBM Flex System Manager 1.3.4.0 IBM Flex System Manager 1.3.3.0 IBM Flex System Manager 1.3.2.1 |
| Not Vulnerable: |
PHP PHP 7.1.7 PHP PHP 5.6.31 kkos oniguruma 6.3.0 |
Discussion
Oniguruma Multiple Memory Corruption Vulnerabilities
Oniguruma is prone to multiple memory-corruption vulnerabilities.
Attackers can exploit these issues to crash the application, resulting in a denial-of-service condition. Due to the nature of these issues, arbitrary code execution may be possible but this has not been confirmed.
Oniguruma 6.2.0 is vulnerable; prior versions may also be affected.
Oniguruma is prone to multiple memory-corruption vulnerabilities.
Attackers can exploit these issues to crash the application, resulting in a denial-of-service condition. Due to the nature of these issues, arbitrary code execution may be possible but this has not been confirmed.
Oniguruma 6.2.0 is vulnerable; prior versions may also be affected.
Exploit / POC
Oniguruma Multiple Memory Corruption Vulnerabilities
Currently, we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Currently, we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution / Fix
Oniguruma Multiple Memory Corruption Vulnerabilities
Solution:
Updates are available. Please see the references or vendor advisory for more information.
Solution:
Updates are available. Please see the references or vendor advisory for more information.
References
Oniguruma Multiple Memory Corruption Vulnerabilities
References:
References:
- Bug 1466730 - (CVE-2017-9224) CVE-2017-9224 oniguruma: Out-of-bounds stack read (Red Hat)
- Bug 1466736 - (CVE-2017-9226) CVE-2017-9226 oniguruma: Heap buffer overflow in n (Red Hat)
- CVE-2017-9224 (Red Hat)
- CVE-2017-9226 (Red Hat)
- fix #55 : Byte value expressed in octal must be smaller than 256 (kkos)
- fix #55 : check too big code point value for single byte value in nex�?� (kkos)
- fix #57 : DATA_ENSURE() check must be before data access (kkos)
- IBM Flex System Manager HomePage (IBM)
- PHP 5 ChangeLog (PHP)
- PHP 7 ChangeLog (PHP)
- Oracle Solaris Third Party Bulletin - October 2018 (Oracle)
- Security Bulletin: Multiple vulnerabilities in php5 affect IBM Flex System Manag (IBM)