CVE Vulnerabilities

CVE-2018-21232

Uncontrolled Recursion

Published: Apr 29, 2020 | Modified: May 14, 2020
CVSS 3.x
5.5
MEDIUM
Source:
NVD
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
CVSS 2.x
4.3 MEDIUM
AV:N/AC:M/Au:N/C:N/I:N/A:P
RedHat/V2
RedHat/V3
5.5 LOW
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
Ubuntu
LOW

re2c before 2.0 has uncontrolled recursion that causes stack consumption in find_fixed_tags.

Weakness

The product does not properly control the amount of recursion that takes place, consuming excessive resources, such as allocated memory or the program stack.

Affected Software

Name Vendor Start Version End Version
Re2c Re2c * 2.0 (excluding)
Re2c Ubuntu bionic *
Re2c Ubuntu devel *
Re2c Ubuntu eoan *
Re2c Ubuntu esm-infra/bionic *
Re2c Ubuntu esm-infra/xenial *
Re2c Ubuntu focal *
Re2c Ubuntu groovy *
Re2c Ubuntu hirsute *
Re2c Ubuntu impish *
Re2c Ubuntu jammy *
Re2c Ubuntu kinetic *
Re2c Ubuntu lunar *
Re2c Ubuntu mantic *
Re2c Ubuntu noble *
Re2c Ubuntu oracular *
Re2c Ubuntu precise/esm *
Re2c Ubuntu trusty *
Re2c Ubuntu xenial *

Potential Mitigations

References