Alpaquita LinuxStreamSecurity Advisory
Search Cve

CVE-2019-6293

Published: January 15, 2019Last modified: February 21, 2024

Description

An issue was discovered in the function mark_beginning_as_normal in nfa.c in flex 2.6.4. There is a stack exhaustion problem caused by the mark_beginning_as_normal function making recursive calls to itself in certain scenarios involving lots of '*' characters. Remote attackers could leverage this vulnerability to cause a denial-of-service.

Severity score breakdown

ParameterValue
Base score5.5
Attack VectorLOCAL
Attack complexityLOW
Privileges requiredNONE
User interactionREQUIRED
ScopeUNCHANGED
ConfidentialityNONE
Integrity impactNONE
Availability impactHIGH
VectorCVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H

Notes

There is no plan to fix it in upstream, see: https://github.com/westes/flex/issues/414#issuecomment-1589244294 According to the above comment, the crash occurs in flex itself, not the scanner produced by flex. So this should not be treated as a vulnerability.

Status

ProductReleasePackageStatus
Alpaquita Linux23 LTSflexWill not fix (2.6.4-r3)
StreamflexWill not fix (2.6.4-r3)

References

ON THIS PAGE