PT-2015-7793 · Philip Hazel+2 · Pcre+2

Published

2015-12-01

·

Updated

2023-02-16

·

CVE-2015-8393

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions PCRE versions prior to 8.38
Description The issue concerns the mishandling of the -q option for binary files by pcregrep in PCRE, potentially allowing remote attackers to obtain sensitive information via a crafted file. This could be exploited through a CGI script that sends stdout data to a client.
Recommendations For versions prior to 8.38, update to version 8.38 or later to resolve the issue.

Fix

Information Disclosure

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2015-8393
SUSE-SU-2016:2971-1
SUSE-SU-2016:3161-1
SUSE-SU-2017:2699-1
SUSE-SU-2017:2700-1
USN-2943-1

Affected Products

Pcre
Suse
Ubuntu