PT-2015-5717 · Philip Hazel+2 · Pcre+2
Publicado
2015-12-01
·
Atualizado
2018-01-05
·
CVE-2015-2327
CVSS v2.0
7.5
Alta
| Vetor | AV:N/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
PCRE versions prior to 8.36
Description
The issue is related to the handling of certain internal recursive back references in regular expressions. Specifically, patterns like /(((a2)|(a*)g<-1>))*/ can cause a denial of service (segmentation fault) or possibly have other unspecified impacts when encountered by affected software. This can be triggered by a crafted regular expression, for example, through a JavaScript RegExp object.
Recommendations
For PCRE versions prior to 8.36, update to version 8.36 or later to resolve the issue.
Exploit
Correção
DoS
Buffer Overflow
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Pcre
Suse
Ubuntu