Lucene search

K
osvGoogleOSV:CVE-2019-20454
HistoryFeb 14, 2020 - 2:15 p.m.

CVE-2019-20454

2020-02-1414:15:10
Google
osv.dev
7

6.3 Medium

AI Score

Confidence

Low

0.001 Low

EPSS

Percentile

51.2%

An out-of-bounds read was discovered in PCRE before 10.34 when the pattern \X is JIT compiled and used to match specially crafted subjects in non-UTF mode. Applications that use PCRE to parse untrusted input may be vulnerable to this flaw, which would allow an attacker to crash the application. The flaw occurs in do_extuni_no_utf in pcre2_jit_compile.c.