PT-2015-7791 · Php Community+2 · Pcre+2

Published

2015-12-01

·

Updated

2023-02-16

·

CVE-2015-8390

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions PCRE versions prior to 8.38
Description The issue concerns how PCRE handles the [: and `` substrings in character classes. This mishandling allows remote attackers to cause a denial of service due to an uninitialized memory read or possibly have other unspecified impacts. The attack can be carried out via a crafted regular expression, as demonstrated by a JavaScript RegExp object encountered by Konqueror.
Recommendations For versions prior to 8.38, update to version 8.38 or later to resolve the issue. As a temporary workaround, consider restricting the use of character classes in regular expressions until a patch is applied. Avoid using the [: and `` substrings in character classes to minimize the risk of exploitation.

Fix

DoS

Use of Uninitialized Resource

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2015-8390
SUSE-SU-2016:2971-1
SUSE-SU-2016:3161-1
SUSE-SU-2017:2699-1
SUSE-SU-2017:2700-1
USN-2943-1

Affected Products

Pcre
Suse
Ubuntu