Lucene search

K
osvGoogleOSV:CVE-2019-19203
HistoryNov 21, 2019 - 9:15 p.m.

CVE-2019-19203

2019-11-2121:15:11
Google
osv.dev
3

6.7 Medium

AI Score

Confidence

Low

0.006 Low

EPSS

Percentile

78.4%

An issue was discovered in Oniguruma 6.x before 6.9.4_rc2. In the function gb18030_mbc_enc_len in file gb18030.c, a UChar pointer is dereferenced without checking if it passed the end of the matched string. This leads to a heap-based buffer over-read.