Wind River Support Network

HomeDefectsLIN1018-3388
Not to be fixed

LIN1018-3388 : Security Advisory - flex - CVE-2019-6293

Created: Jan 14, 2019    Updated: Aug 8, 2022
Resolved Date: Aug 8, 2022
Found In Version: unknown
Severity: Standard
Applicable for: Wind River Linux LTS 18
Component/s: Userspace

Description

An issue was discovered in the function mark_beginning_as_normal in nfa.c in flex 2.6.4. There is a stack exhaustion problem caused by the mark_beginning_as_normal function making recursive calls to itself in certain scenarios involving lots of '*' characters. Remote attackers could leverage this vulnerability to cause a denial-of-service.

https://nvd.nist.gov/vuln/detail/CVE-2019-6293

CVEs


Live chat
Online