PT-2005-5613 · Pcre+2 · Pcre-Devel+5

Ludwig Nussel

·

Published

1970-01-01

·

Updated

2017-10-11

·

CVE-2006-7230

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions PCRE library versions prior to 7.0 libpcre versions prior to 7.3-r1 pcre-32bit versions (affected versions not specified) pcre versions (affected versions not specified) pcre-devel versions (affected versions not specified)
Description The issue allows context-dependent attackers to cause a denial of service via crafted regular expressions, potentially leading to a crash of the PCRE or glibc. Multiple vulnerabilities in the libpcre, pcre-32bit, pcre, and pcre-devel packages may lead to a violation of confidentiality, integrity, and availability of protected information. These vulnerabilities can be exploited remotely.
Recommendations For PCRE library versions prior to 7.0, update to version 7.0 or later to resolve the issue. For libpcre versions prior to 7.3-r1, update to version 7.3-r1 or later to resolve the issue. For pcre-32bit, pcre, and pcre-devel, at the moment, there is no information about a newer version that contains a fix for this vulnerability.

DoS

Buffer Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2015-04723
BDU:2015-04724
BDU:2015-04725
BDU:2015-09569
CVE-2006-7230
DSA-1570-1
RHSA-2007:1059
RHSA-2007:1068
RHSA-2007_1059
RHSA-2007_1068

Affected Products

Pcre
Red Hat
Glibc
Libpcre
Pcre-32Bit
Pcre-Devel