PT-2019-8041 · Pcre+2 · Pcre+2

Zhang Jiawang

·

Published

2018-07-12

·

Updated

2024-08-05

·

CVE-2017-16231

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions PCRE version 8.41
Description The issue is related to a crash overflow in the function match() in pcre exec.c due to a self-recursive call. This occurs after compiling and running a pcretest load test proof of concept. It's worth noting that third parties have disputed the relevance of this report, suggesting that options are available to limit the amount of stack used, potentially mitigating the issue.
Recommendations For PCRE version 8.41, consider using options that limit the amount of stack used to mitigate the risk of a crash overflow. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Buffer Overflow

Weakness Enumeration

Related Identifiers

ALT-PU-2018-2007
CVE-2017-16231

Affected Products

Alt Linux
Debian
Pcre