MGASA-2019-0253
Advisory lineage Upstream: 2 Downstream: 0
Upstream
Published: 06 Sept 2019, 21:09
Last modified:16 Apr 2026, 04:26
Vulnerability Summary
Overall Risk (default)
minimal
0/100 CVSS Score
No data
EPSS Score
No data
KEV
Not listed
Ransomware
No reports
Public exploits
None found
Dark Web
Not detected
Timeline
06 Sept 2019, 21:09
Published
Vulnerability first disclosed
16 Apr 2026, 04:26
Last Modified
Vulnerability information updated
Description
Updated php packages fix security vulnerabilities Updated php packages fix security vulnerabilities: A use-after-free in onig_new_deluxe() in regext.c in the bundled Oniguruma allows attackers to potentially cause information disclosure, denial of service, or possibly code execution by providing a crafted regular expression (CVE-2019-13224). A NULL Pointer Dereference in match_at() in regexec.c in the bundled Oniguruma allows attackers to potentially cause denial of service by providing a crafted regular expression (CVE-2019-13225). For other fixes in this update, see the referenced changelog.
Affected Systems
- mageia•php
< 7.3.9-1.mga7