Lucene search

K
f5F5F5:K26346590
HistoryNov 05, 2019 - 12:00 a.m.

K26346590 : GNU C Library vulnerabilities CVE-2019-9192 and CVE-2018-20796

2019-11-0500:00:00
my.f5.com
30

7.3 High

AI Score

Confidence

High

0.006 Low

EPSS

Percentile

79.1%

Security Advisory Description

DISPUTED In the GNU C Library (aka glibc or libc6) through 2.29, check_dst_limits_calc_pos_1 in posix/regexec.c has Uncontrolled Recursion, as demonstrated by ‘(|)(\\1\\1)*’ in grep, a different issue than CVE-2018-20796. NOTE: the software maintainer disputes that this is a vulnerability because the behavior occurs only with a crafted pattern.

In the GNU C Library (aka glibc or libc6) through 2.29, check_dst_limits_calc_pos_1 in posix/regexec.c has Uncontrolled Recursion, as demonstrated by ‘(\227|)(\\1\\1|t1|\\\2537)+’ in grep.

Impact

There is no impact; F5 products are not affected by this vulnerability.

7.3 High

AI Score

Confidence

High

0.006 Low

EPSS

Percentile

79.1%