PT-2005-5611 · Pcre+1 · Pcre-Devel+4

Andrews Salomon

·

Published

1970-01-01

·

Updated

2023-02-13

·

CVE-2006-7227

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions PCRE library versions prior to 6.7 libpcre versions prior to 7.3-r1 pcre-32bit (affected versions not specified) pcre (affected versions not specified) pcre-devel (affected versions not specified)
Description The issue is related to an integer overflow in the Perl-Compatible Regular Expression (PCRE) library, which allows context-dependent attackers to execute arbitrary code via a regular expression containing a large number of named subpatterns (name count) or long subpattern names (max name size), triggering a buffer overflow. Multiple vulnerabilities in the PCRE library can lead to a violation of confidentiality, integrity, and availability of protected information, and can be exploited remotely.
Recommendations For PCRE library versions prior to 6.7, update to version 6.7 or later. For libpcre versions prior to 7.3-r1, update to version 7.3-r1 or later. For pcre-32bit, pcre, and pcre-devel, at the moment, there is no information about a newer version that contains a fix for this vulnerability. As a temporary workaround, consider restricting access to the vulnerable components until a patch is available.

Buffer Overflow

Weakness Enumeration

Related Identifiers

BDU:2015-04723
BDU:2015-04724
BDU:2015-04725
BDU:2015-09569
CVE-2006-7227
DSA-1570-1
RHSA-2007:1052
RHSA-2007_1052

Affected Products

Pcre
Red Hat
Libpcre
Pcre-32Bit
Pcre-Devel