Advisories ยป MGASA-2020-0452

Updated oniguruma packages fix security vulnerability

Publication date: 08 Dec 2020
Modification date: 08 Dec 2020
Type: security
Affected Mageia releases : 7
CVE: CVE-2020-26159

Description

In Oniguruma, an attacker able to supply a regular expression for compilation
may be able to overflow a buffer by one byte in concat_opt_exact_str in
src/regcomp.c (CVE-2020-26159).
                

References

SRPMS

7/core