PT-2015-3437 · Pcre+5 · Pcre+5

Published

2015-11-24

·

Updated

2023-02-16

·

CVE-2015-8391

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions PCRE versions prior to 8.38
Description The issue is related to the pcre compile function in the PCRE library, which mishandles certain [: nesting in regular expressions. This can be exploited by remote attackers to cause a denial of service, potentially leading to CPU consumption, via a crafted regular expression. The vulnerability may have other unspecified impacts.
Recommendations For versions prior to 8.38, update to version 8.38 or later to resolve the issue. As a temporary workaround, consider restricting the use of the pcre compile function until a patch is available. Avoid using crafted regular expressions that may exploit the vulnerability in the pcre compile function.

Fix

DoS

Buffer Overflow

Weakness Enumeration

Related Identifiers

ALT-PU-2015-2023
BDU:2022-04560
CESA-2016_1025
CVE-2015-8391
RHSA-2016:1025
RHSA-2016:1132
RHSA-2016:2750
RHSA-2016_1025
SUSE-SU-2016:2971-1
SUSE-SU-2016:3161-1
SUSE-SU-2017:2699-1
SUSE-SU-2017:2700-1
USN-2943-1

Affected Products

Alt Linux
Centos
Pcre
Red Hat
Suse
Ubuntu