Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2015-5073

Опубликовано: 13 дек. 2016
Источник: nvd
CVSS3: 9.1
CVSS2: 6.4
EPSS Низкий

Описание

Heap-based buffer overflow in the find_fixedlength function in pcre_compile.c in PCRE before 8.38 allows remote attackers to cause a denial of service (crash) or obtain sensitive information from heap memory and possibly bypass the ASLR protection mechanism via a crafted regular expression with an excess closing parenthesis.

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:ibm:powerkvm:2.1:*:*:*:*:*:*:*
cpe:2.3:a:ibm:powerkvm:3.1:*:*:*:*:*:*:*
Конфигурация 2
cpe:2.3:a:pcre:pcre:*:*:*:*:*:*:*:*
Версия до 8.37 (включая)

EPSS

Процентиль: 71%
0.00714
Низкий

9.1 Critical

CVSS3

6.4 Medium

CVSS2

Дефекты

CWE-119

Связанные уязвимости

CVSS3: 9.1
ubuntu
больше 8 лет назад

Heap-based buffer overflow in the find_fixedlength function in pcre_compile.c in PCRE before 8.38 allows remote attackers to cause a denial of service (crash) or obtain sensitive information from heap memory and possibly bypass the ASLR protection mechanism via a crafted regular expression with an excess closing parenthesis.

redhat
около 10 лет назад

Heap-based buffer overflow in the find_fixedlength function in pcre_compile.c in PCRE before 8.38 allows remote attackers to cause a denial of service (crash) or obtain sensitive information from heap memory and possibly bypass the ASLR protection mechanism via a crafted regular expression with an excess closing parenthesis.

CVSS3: 9.1
debian
больше 8 лет назад

Heap-based buffer overflow in the find_fixedlength function in pcre_co ...

CVSS3: 9.1
github
около 3 лет назад

Heap-based buffer overflow in the find_fixedlength function in pcre_compile.c in PCRE before 8.38 allows remote attackers to cause a denial of service (crash) or obtain sensitive information from heap memory and possibly bypass the ASLR protection mechanism via a crafted regular expression with an excess closing parenthesis.

oracle-oval
около 9 лет назад

ELSA-2016-1025: pcre security update (IMPORTANT)

EPSS

Процентиль: 71%
0.00714
Низкий

9.1 Critical

CVSS3

6.4 Medium

CVSS2

Дефекты

CWE-119