{"schema_version":"1.8.0","id":"CVE-2019-19246","published":"2019-11-25T17:15:11.887Z","modified":"2026-08-07T14:52:51.303975Z","related":["ALSA-2020:3662","SUSE-SU-2022:3327-1","openSUSE-SU-2024:11111-1"],"details":"Oniguruma through 6.9.3, as used in PHP 7.3.x and other products, has a heap-based buffer over-read in str_lower_case_match in regexec.c.","affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/kkos/oniguruma","events":[{"introduced":"0"},{"last_affected":"813592905c2d55ff7f70fc92bf775c859d6ed48e"},{"fixed":"d3e402928b6eb3327f8f7d59a9edfa622fec557b"}],"database_specific":{"cpe":"cpe:2.3:a:oniguruma_project:oniguruma:*:*:*:*:*:*:*:*","extracted_events":[{"introduced":"0"},{"last_affected":"6.9.3"}],"source":["CPE_RANGE","REFERENCES"]}}],"versions":["v6.9.3","v6.9.2_rc3","v6.9.2","v6.9.2_rc2","v6.9.2_rc1","v6.9.1","v6.9.0","v6.8.2","v6.8.1","v6.8.0","v6.7.1","v6.7.0","v6.6.1","v6.6.0","v6.5.0","v6.4.0","v6.3.0","v6.2.0","v6.1.3","v5.9.6","v6.1.2","v6.1.1","v6.1.0","v6.0.0"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2019-19246.json","vanir_signatures":[{"deprecated":false,"digest":{"line_hashes":["62515007490554007865331787131035268207","73060259964332736538643090030886107933","240203263475203359359784711152491354249","158627744619430761962932360405786758087"],"threshold":0.9},"id":"CVE-2019-19246-ee72ec58","signature_type":"Line","signature_version":"v1","source":"https://github.com/kkos/oniguruma/commit/d3e402928b6eb3327f8f7d59a9edfa622fec557b","target":{"file":"src/regexec.c"}},{"deprecated":false,"digest":{"function_hash":"301772738909245608982934055287646460906","length":390},"id":"CVE-2019-19246-f787398e","signature_type":"Function","signature_version":"v1","source":"https://github.com/kkos/oniguruma/commit/d3e402928b6eb3327f8f7d59a9edfa622fec557b","target":{"file":"src/regexec.c","function":"str_lower_case_match"}}],"vanir_signatures_modified":"2026-08-07T14:52:51Z"}},{"ranges":[{"type":"GIT","repo":"https://github.com/php/php-src","events":[{"introduced":"52ace952a1b65ca80fc2617f11c2fa6dd03f51bd"},{"fixed":"7d61aa2b2132a07e79c5926f38bd621187e8672c"}],"database_specific":{"cpe":"cpe:2.3:a:php:php:*:*:*:*:*:*:*:*","extracted_events":[{"introduced":"7.3.0"},{"fixed":"7.3.10"}],"source":"CPE_RANGE"}}],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2019-19246.json"}}],"references":[{"type":"WEB","url":"https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/NO267PLHGYZSWX3XTRPKYBKD4J3YOU5V/"},{"type":"ADVISORY","url":"https://bugs.php.net/bug.php?id=78559"},{"type":"ADVISORY","url":"https://lists.debian.org/debian-lts-announce/2019/12/msg00002.html"},{"type":"ADVISORY","url":"https://usn.ubuntu.com/4460-1/"},{"type":"FIX","url":"https://github.com/kkos/oniguruma/commit/d3e402928b6eb3327f8f7d59a9edfa622fec557b"}],"database_specific":{"unresolved_ranges":[{"cpes":["cpe:2.3:o:canonical:ubuntu_linux:14.04:*:*:*:esm:*:*:*"],"extracted_events":[{"introduced":"14.04"},{"last_affected":"14.04"}],"source":"CPE_STRING","vendor_product":"canonical:ubuntu_linux"},{"cpes":["cpe:2.3:o:debian:debian_linux:8.0:*:*:*:*:*:*:*"],"extracted_events":[{"introduced":"8.0"},{"last_affected":"8.0"}],"source":"CPE_STRING","vendor_product":"debian:debian_linux"},{"cpes":["cpe:2.3:o:fedoraproject:fedora:31:*:*:*:*:*:*:*"],"extracted_events":[{"introduced":"31"},{"last_affected":"31"}],"source":"CPE_STRING","vendor_product":"fedoraproject:fedora"}]},"severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"}]}