PT-2017-17605 · Pcre+2 · Pcre+2

Agostino Sarubbo

·

Published

2017-03-23

·

Updated

2021-11-10

·

CVE-2017-7244

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions PCRE version 8.40
Description The issue allows remote attackers to cause a denial of service, specifically an invalid memory read, via a crafted file. This is due to a problem in the pcre32 xclass function in pcre xclass.c in libpcre1.
Recommendations For PCRE version 8.40, consider updating to a newer version that contains a fix for this issue, as using a crafted file can lead to a denial of service.

Fix

DoS

Out of bounds Read

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2017-1815
CVE-2017-7244
MGASA-2017-0454
SUSE-SU-2021:3652-1

Affected Products

Alt Linux
Pcre
Suse