Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2015-2325

Опубликовано: 14 янв. 2020
Источник: debian
EPSS Низкий

Описание

The compile_branch function in PCRE before 8.37 allows context-dependent attackers to compile incorrect code, cause a denial of service (out-of-bounds heap read and crash), or possibly have other unspecified impact via a regular expression with a group containing a forward reference repeated a large number of times within a repeated outer group that has a zero minimum quantifier.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
pcre3fixed2:8.35-7.2package
pcre3fixed2:8.35-3.3+deb8u1jessiepackage

Примечания

  • http://bugs.exim.org/show_bug.cgi?id=1591

  • Fixed by: http://vcs.pcre.org/pcre?view=revision&revision=1528

  • Reproducer leads to "Failed: internal error: previously-checked referenced subpattern not found at offset 17"

  • Upstream claims that it should though be the same bug:

  • http://bugs.exim.org/show_bug.cgi?id=1591#c1

  • Comment from upstream: Probably every version since the support for forward referencing

  • was introduced is affected.

EPSS

Процентиль: 68%
0.0057
Низкий

Связанные уязвимости

CVSS3: 7.8
ubuntu
больше 5 лет назад

The compile_branch function in PCRE before 8.37 allows context-dependent attackers to compile incorrect code, cause a denial of service (out-of-bounds heap read and crash), or possibly have other unspecified impact via a regular expression with a group containing a forward reference repeated a large number of times within a repeated outer group that has a zero minimum quantifier.

redhat
около 10 лет назад

The compile_branch function in PCRE before 8.37 allows context-dependent attackers to compile incorrect code, cause a denial of service (out-of-bounds heap read and crash), or possibly have other unspecified impact via a regular expression with a group containing a forward reference repeated a large number of times within a repeated outer group that has a zero minimum quantifier.

CVSS3: 7.8
nvd
больше 5 лет назад

The compile_branch function in PCRE before 8.37 allows context-dependent attackers to compile incorrect code, cause a denial of service (out-of-bounds heap read and crash), or possibly have other unspecified impact via a regular expression with a group containing a forward reference repeated a large number of times within a repeated outer group that has a zero minimum quantifier.

CVSS3: 7.8
github
около 3 лет назад

The compile_branch function in PCRE before 8.37 allows context-dependent attackers to compile incorrect code, cause a denial of service (out-of-bounds heap read and crash), or possibly have other unspecified impact via a regular expression with a group containing a forward reference repeated a large number of times within a repeated outer group that has a zero minimum quantifier.

suse-cvrf
почти 10 лет назад

Security update for mariadb

EPSS

Процентиль: 68%
0.0057
Низкий