oniguruma is vulnerable to Heap-based buffer over-read. It is possible because of a flaw in the function gb18030_mbc_enc_len
in file gb18030.c
.
access.redhat.com/documentation/en-us/red_hat_software_collections/3/html/3.6_release_notes/
access.redhat.com/errata/RHSA-2020:5275
access.redhat.com/security/updates/classification/#moderate
github.com/kkos/oniguruma/issues/163
github.com/kkos/oniguruma/releases/tag/v6.9.4_rc2
github.com/ManhNDd/CVE-2019-19203
github.com/tarantula-team/CVE-2019-19203
lists.fedoraproject.org/archives/list/[email protected]/message/NO267PLHGYZSWX3XTRPKYBKD4J3YOU5V/
lists.fedoraproject.org/archives/list/[email protected]/message/V3MBNW6Z4DOXSCNWGBLQ7OA3OGUJ44WL/