PT-2015-6097 · Pcre+3 · Pcre2+4

Wen Guanxing

·

Published

2015-06-01

·

Updated

2023-12-20

·

CVE-2015-3210

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions PCRE versions 8.34 through 8.37 PCRE2 version 10.10
Description A heap-based buffer overflow issue allows remote attackers to execute arbitrary code via a crafted regular expression.
Recommendations For PCRE versions 8.34 through 8.37, update to a version outside of this range to resolve the issue. For PCRE2 version 10.10, update to a version later than 10.10 to resolve the issue. As a temporary workaround, consider restricting the use of crafted regular expressions until a patch is available.

Exploit

Fix

RCE

Memory Corruption

Weakness Enumeration

Related Identifiers

ALT-PU-2015-2023
CVE-2015-3210
RHSA-2016:1132
RHSA-2016:2750
SUSE-SU-2016:2971-1
SUSE-SU-2016:3161-1
SUSE-SU-2017:2699-1
SUSE-SU-2017:2700-1
USN-2694-1
USN-2943-1

Affected Products

Alt Linux
Pcre
Pcre2
Suse
Ubuntu