Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2014-8964

Опубликовано: 18 нояб. 2014
Источник: redhat
CVSS2: 4.3
EPSS Низкий

Описание

Heap-based buffer overflow in PCRE 8.36 and earlier allows remote attackers to cause a denial of service (crash) or have other unspecified impact via a crafted regular expression, related to an assertion that allows zero repeats.

A flaw was found in the way PCRE handled certain malformed regular expressions. This issue could cause an application (for example, Konqueror) linked against PCRE to crash while parsing malicious regular expressions.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 5pcreNot affected
Red Hat Enterprise Linux 6pcreNot affected
Red Hat Software Collectionsphp54-phpWill not fix
Red Hat Software Collectionsphp55-phpWill not fix
Red Hat Enterprise Linux 7pcreFixedRHSA-2015:033005.03.2015

Показывать по

Дополнительная информация

Статус:

Low
Дефект:
CWE-119
https://bugzilla.redhat.com/show_bug.cgi?id=1166147pcre: incorrect handling of zero-repeat assertion conditions

EPSS

Процентиль: 83%
0.02089
Низкий

4.3 Medium

CVSS2

Связанные уязвимости

ubuntu
больше 10 лет назад

Heap-based buffer overflow in PCRE 8.36 and earlier allows remote attackers to cause a denial of service (crash) or have other unspecified impact via a crafted regular expression, related to an assertion that allows zero repeats.

nvd
больше 10 лет назад

Heap-based buffer overflow in PCRE 8.36 and earlier allows remote attackers to cause a denial of service (crash) or have other unspecified impact via a crafted regular expression, related to an assertion that allows zero repeats.

debian
больше 10 лет назад

Heap-based buffer overflow in PCRE 8.36 and earlier allows remote atta ...

github
больше 3 лет назад

Heap-based buffer overflow in PCRE 8.36 and earlier allows remote attackers to cause a denial of service (crash) or have other unspecified impact via a crafted regular expression, related to an assertion that allows zero repeats.

oracle-oval
больше 10 лет назад

ELSA-2015-0330: pcre security and enhancement update (LOW)

EPSS

Процентиль: 83%
0.02089
Низкий

4.3 Medium

CVSS2