1
PublicDateAtUSN: 2017-05-24
2
Candidate: CVE-2017-9228
5
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-9228
6
https://usn.ubuntu.com/usn/usn-3382-1
7
https://usn.ubuntu.com/usn/usn-3382-2
9
An issue was discovered in Oniguruma 6.2.0, as used in Oniguruma-mod in
10
Ruby through 2.4.1 and mbstring in PHP through 7.1.5. A heap out-of-bounds
11
write occurs in bitset_set_range() during regular expression compilation
12
due to an uninitialized variable from an incorrect state transition. An
13
incorrect state transition in parse_char_class() could create an execution
14
path that leaves a critical local variable uninitialized until it's used as
15
an index, resulting in an out-of-bounds write memory corruption.
19
http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=863316
20
https://github.com/kkos/oniguruma/issues/60
26
upstream: https://github.com/kkos/oniguruma/commit/3b63d12038c8d8fc278e81c942fa9bec7c704c8b
27
upstream_libonig: needs-triage
28
precise/esm_libonig: DNE
29
trusty_libonig: needed
30
vivid/stable-phone-overlay_libonig: DNE
31
vivid/ubuntu-core_libonig: DNE
32
xenial_libonig: needed
33
yakkety_libonig: ignored (reached end-of-life)
34
zesty_libonig: ignored (reached end-of-life)
35
artful_libonig: needed
36
bionic_libonig: needed
40
upstream: https://github.com/php/php-src/commit/703be4f77e662837b64499b0d046a5c8d06a98b9
41
upstream_php5: needs-triage
42
precise/esm_php5: released (5.3.10-1ubuntu3.28)
43
trusty_php5: released (5.5.9+dfsg-1ubuntu4.22)
44
vivid/ubuntu-core_php5: DNE
52
upstream: https://github.com/php/php-src/commit/1c845d295037702d63097e2216b3c5db53f79273
53
upstream_php7.0: needs-triage
54
precise/esm_php7.0: DNE
56
vivid/ubuntu-core_php7.0: DNE
57
xenial_php7.0: released (7.0.22-0ubuntu0.16.04.1)
58
zesty_php7.0: released (7.0.22-0ubuntu0.17.04.1)
64
upstream: https://github.com/php/php-src/commit/1c845d295037702d63097e2216b3c5db53f79273
65
upstream_php7.1: needs-triage
66
precise/esm_php7.1: DNE
68
vivid/ubuntu-core_php7.1: DNE
71
artful_php7.1: released (7.1.8-1ubuntu1)