PT-2022-6873 · Pcre2+5 · Pcre2+5

Worldexecute

·

Published

2022-08-16

·

Updated

2024-12-12

·

CVE-2022-41409

CVSS v2.0

7.8

High

VectorAV:N/AC:L/Au:N/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions PCRE2 versions prior to 10.41
Description The issue is related to an integer overflow vulnerability in the pcre2test command of the PCRE2 regular expression library. This vulnerability can be exploited by a remote attacker to cause a denial of service or other unspecified impacts via negative input.
Recommendations For versions prior to 10.41, update to version 10.41 or later to resolve the issue. As a temporary workaround, consider restricting the use of the pcre2test command until a patch is available.

Exploit

Fix

DoS

Integer Overflow

Improper Resource Release

Weakness Enumeration

Related Identifiers

ALT-PU-2023-4658
ALT-PU-2023-4659
ALT-PU-2023-5628
AZL-27500
BDU:2023-05302
CVE-2022-41409
OESA-2023-1482
OPENSUSE-SU-2023_3327-1
ROSA-SA-2024-2378
SUSE-SU-2023:3210-1
SUSE-SU-2023:3327-1
SUSE-SU-2023:3328-1
SUSE-SU-2023_3327-1
SUSE-SU-2023_3328-1

Affected Products

Alt Linux
Astra Linux
Debian
Pcre2
Red Os
Suse