PT-2008-1088 · Pcre+1 · Pcre Library+1

Tavis Ormandy

·

Published

2008-07-07

·

Updated

2022-08-01

·

CVE-2008-2371

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions PCRE library versions prior to 7.7
Description The issue is related to a heap-based buffer overflow in the PCRE library, specifically in the pcre compile.c file. This allows context-dependent attackers to cause a denial of service or possibly execute arbitrary code via a specially crafted regular expression. The vulnerability can be exploited remotely, potentially leading to a violation of confidentiality, integrity, and availability of protected information.
Recommendations For PCRE library versions prior to 7.7, update to version 7.7 or later to resolve the issue. As a temporary workaround, consider restricting the use of the pcre compile() function until a patch is available. Avoid using complex regular expressions that begin with an option and contain multiple branches in the affected PCRE library versions.

Exploit

Fix

DoS

Memory Corruption

Weakness Enumeration

Related Identifiers

BDU:2015-09343
CVE-2008-2371
DSA-1602-1
DTSA-145-1
HPSBUX02431
HPSBUX02465
OPENSUSE-SU-2024:10791-1

Affected Products

Hp-Ux
Pcre Library