PT-2015-7793 · Philip Hazel+2 · Pcre+2
Publicado
2015-12-01
·
Atualizado
2023-02-16
·
CVE-2015-8393
CVSS v3.1
7.5
Alta
| Vetor | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
PCRE versions prior to 8.38
Description
The issue concerns the mishandling of the -q option for binary files by pcregrep in PCRE, potentially allowing remote attackers to obtain sensitive information via a crafted file. This could be exploited through a CGI script that sends stdout data to a client.
Recommendations
For versions prior to 8.38, update to version 8.38 or later to resolve the issue.
Correção
Information Disclosure
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Pcre
Suse
Ubuntu