CVE-2019-9192

SOURCE - nist

Summary

In the GNU C Library (aka glibc or libc6) through 2.29, check_dst_limits_calc_pos_1 in posix/regexec.c has Uncontrolled Recursion, as demonstrated by '(|)(\1\1)*' in grep, a different issue than CVE-2018-20796. NOTE: the software maintainer disputes that this is a vulnerability because the behavior occurs only with a crafted pattern

EPSS Score: 0.00108 (0.435)

Common Weakness Enumeration (CWE)

SOURCE - nist

Uncontrolled Recursion

SOURCE - redhat

Uncontrolled Recursion


debian

CREATED


UPDATED



EXPLOITABILITY SCORE

-


EXPLOITS FOUND
-

COMMON WEAKNESS ENUMERATION (CWE)-

CVSS SCORE

N/Alow
PackageTypeOS NameOS VersionAffected RangesFix Versions
debian/glibcdebdebian12>=2.36-9+deb12u4Not yet available
debian/glibcdebdebianunstable>=2.38-11Not yet available
debian/glibcdebdebian13>=2.38-11Not yet available
debian/glibcdebdebian11>=2.31-13+deb11u8Not yet available
debian/glibcdebdebian10>=2.28-10+deb10u1Not yet available

Severity and metrics

No CVSS data available from this source.

nist

CREATED


UPDATED



EXPLOITABILITY SCORE

3.9


EXPLOITS FOUND

COMMON WEAKNESS ENUMERATION (CWE)

CVSS SCORE

7.5high

ubuntu

CREATED


UPDATED



EXPLOITABILITY SCORE

3.9


EXPLOITS FOUND
-

COMMON WEAKNESS ENUMERATION (CWE)-

CVSS SCORE

7.5low

redhat

CREATED


UPDATED



EXPLOITABILITY SCORE

1.3


EXPLOITS FOUND
-

COMMON WEAKNESS ENUMERATION (CWE)

CVSS SCORE

2.8low

inthewild

CREATED


UPDATED



EXPLOITABILITY SCORE

-


EXPLOITS FOUND

-


COMMON WEAKNESS ENUMERATION (CWE)-
RATING UNAVAILABLE FROM SOURCE