PT-2007-1501 · Pcre+1 · Pcre Library+1

Ludwig Nussel

·

Published

2007-11-29

·

Updated

2017-10-11

·

CVE-2006-7226

CVSS v2.0

4.3

Medium

VectorAV:N/AC:M/Au:N/C:N/I:N/A:P
Name of the Vulnerable Software and Affected Versions PCRE library versions prior to 6.7
Description The issue arises from improper calculation of compiled memory allocation for regular expressions involving quantified subpatterns with named recursion or subroutine references. This allows context-dependent attackers to cause a denial of service, potentially leading to errors or crashes.
Recommendations For versions prior to 6.7, update to version 6.7 or later to resolve the issue.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2006-7226
RHSA-2007:1059
RHSA-2007:1068
RHSA-2007_1059
RHSA-2007_1068

Affected Products

Pcre Library
Red Hat