PT-2019-8041 · Pcre+2 · Pcre+2
Zhang Jiawang
·
Publicado
2018-07-12
·
Atualizado
2024-08-05
·
CVE-2017-16231
CVSS v3.1
5.5
Média
| Vetor | AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
PCRE version 8.41
Description
The issue is related to a crash overflow in the function match() in pcre exec.c due to a self-recursive call. This occurs after compiling and running a pcretest load test proof of concept. It's worth noting that third parties have disputed the relevance of this report, suggesting that options are available to limit the amount of stack used, potentially mitigating the issue.
Recommendations
For PCRE version 8.41, consider using options that limit the amount of stack used to mitigate the risk of a crash overflow.
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
Buffer Overflow
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Alt Linux
Debian
Pcre