Description
Oniguruma through 6.9.3, as used in PHP 7.3.x and other products, has a heap-based buffer over-read in str_lower_case_match in regexec.c.
Remediation
References
Related Vulnerabilities
Magento Improper Control of Generation of Code ('Code Injection') Vulnerability (CVE-2019-7903)
WordPress Plugin Custom Background 'uploadify.php' Arbitrary File Upload (1.01)
Oracle JRE CVE-2013-1540 Vulnerability (CVE-2013-1540)
WordPress Plugin LearnDash LMS Multiple Information Disclosure Vulnerabilities (4.10.2)