A NULL Pointer Dereference in match_at() in regexec.c in Oniguruma 6.9.2 allows attackers to potentially cause denial of service by providing a crafted regular expression. Oniguruma issues often affect Ruby, as well as common optional libraries for PHP and Rust.
A NULL pointer dereference occurs when the application dereferences a pointer that it expects to be valid, but is NULL, typically causing a crash or exit.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Oniguruma | Oniguruma_project | 6.9.2 (including) | 6.9.2 (including) |
Red Hat Enterprise Linux 8 | RedHat | php:7.3-8020020200715124551.ceb1cf90 | * |
Red Hat Enterprise Linux 8 | RedHat | oniguruma-0:6.8.2-2.el8 | * |
Libonig | Ubuntu | devel | * |
Libonig | Ubuntu | disco | * |
Libonig | Ubuntu | eoan | * |
Libonig | Ubuntu | trusty | * |
Libonig | Ubuntu | upstream | * |