CVE-2017-9228
oniguruma: Out-of-bounds heap write in bitset_set_range()
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
1Exploited in Wild
-Decision
Descriptions
An issue was discovered in Oniguruma 6.2.0, as used in Oniguruma-mod in Ruby through 2.4.1 and mbstring in PHP through 7.1.5. A heap out-of-bounds write occurs in bitset_set_range() during regular expression compilation due to an uninitialized variable from an incorrect state transition. An incorrect state transition in parse_char_class() could create an execution path that leaves a critical local variable uninitialized until it's used as an index, resulting in an out-of-bounds write memory corruption.
Se descubrió un problema en Oniguruma versión 6.2.0, tal como es usado en Oniguruma-mod en Ruby hasta la versión 2.4.1 y mbstring en PHP hasta la versión 7.1.5. Se produce una escritura fuera del límite de la pila en bitset_set_range() durante la compilación de expresiones regulares debido a una variable no inicializada de una transición de estado incorrecta. Una transición de estado incorrecta en parse_char_class() podría diseñar una ruta (path) de ejecución que deje una variable local crítica sin inicializar hasta que se utilice como un índice, resultando en una corrupción de memoria de escritura fuera de los límites.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2017-05-24 CVE Reserved
- 2017-05-24 CVE Published
- 2023-05-08 EPSS Updated
- 2024-08-05 CVE Updated
- 2024-08-05 First Exploit
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
- CWE-122: Heap-based Buffer Overflow
- CWE-787: Out-of-bounds Write
CAPEC
References (5)
URL | Tag | Source |
---|
URL | Date | SRC |
---|---|---|
https://github.com/kkos/oniguruma/issues/60 | 2024-08-05 |
URL | Date | SRC |
---|---|---|
https://github.com/kkos/oniguruma/commit/3b63d12038c8d8fc278e81c942fa9bec7c704c8b | 2022-07-20 |
URL | Date | SRC |
---|---|---|
https://access.redhat.com/errata/RHSA-2018:1296 | 2022-07-20 | |
https://access.redhat.com/security/cve/CVE-2017-9228 | 2018-05-03 | |
https://bugzilla.redhat.com/show_bug.cgi?id=1466740 | 2018-05-03 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Oniguruma Project Search vendor "Oniguruma Project" | Oniguruma Search vendor "Oniguruma Project" for product "Oniguruma" | 6.2.0 Search vendor "Oniguruma Project" for product "Oniguruma" and version "6.2.0" | - |
Affected
| ||||||
Php Search vendor "Php" | Php Search vendor "Php" for product "Php" | >= 5.6.0 < 5.6.31 Search vendor "Php" for product "Php" and version " >= 5.6.0 < 5.6.31" | - |
Affected
| ||||||
Php Search vendor "Php" | Php Search vendor "Php" for product "Php" | >= 7.0.0 < 7.0.21 Search vendor "Php" for product "Php" and version " >= 7.0.0 < 7.0.21" | - |
Affected
| ||||||
Php Search vendor "Php" | Php Search vendor "Php" for product "Php" | >= 7.1.0 < 7.1.7 Search vendor "Php" for product "Php" and version " >= 7.1.0 < 7.1.7" | - |
Affected
|