PT-2015-3437 · Pcre+5 · Pcre+5
CVE-2015-8391
·
Publicado
2015-11-24
·
Atualizado
2023-02-16
CVSS v3.1
9.8
Crítica
| Vetor | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
PCRE versions prior to 8.38
Description
The issue is related to the
pcre compile function in the PCRE library, which mishandles certain [: nesting in regular expressions. This can be exploited by remote attackers to cause a denial of service, potentially leading to CPU consumption, via a crafted regular expression. The vulnerability may have other unspecified impacts.Recommendations
For versions prior to 8.38, update to version 8.38 or later to resolve the issue. As a temporary workaround, consider restricting the use of the
pcre compile function until a patch is available. Avoid using crafted regular expressions that may exploit the vulnerability in the pcre compile function.Correção
DoS
Buffer Overflow
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Alt Linux
Centos
Pcre
Red Hat
Suse
Ubuntu