Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2015-8394

Опубликовано: 23 нояб. 2015
Источник: redhat
CVSS2: 4.3
EPSS Низкий

Описание

PCRE before 8.38 mishandles the (?() and (?(R) conditions, which allows remote attackers to cause a denial of service (integer overflow) or possibly have unspecified other impact via a crafted regular expression, as demonstrated by a JavaScript RegExp object encountered by Konqueror.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Directory Server 8pcreWill not fix
Red Hat Enterprise Linux 5pcreWill not fix
Red Hat Enterprise Linux 6glib2Will not fix
Red Hat Enterprise Linux 6pcreWill not fix
Red Hat Enterprise Linux 7glib2Will not fix
Red Hat Enterprise Linux 7pcreWill not fix
Red Hat Enterprise Linux 7virtuoso-opensourceWill not fix
Red Hat JBoss Enterprise Web Server 1httpdWill not fix
Red Hat JBoss Enterprise Web Server 2httpdWill not fix
Red Hat JBoss Enterprise Web Server 3pcreWill not fix

Показывать по

Дополнительная информация

Дефект:
CWE-190
https://bugzilla.redhat.com/show_bug.cgi?id=1287702pcre: Integer overflow caused by missing check for certain conditions (8.38/31)

EPSS

Процентиль: 86%
0.03025
Низкий

4.3 Medium

CVSS2

Связанные уязвимости

CVSS3: 9.8
ubuntu
больше 9 лет назад

PCRE before 8.38 mishandles the (?(<digits>) and (?(R<digits>) conditions, which allows remote attackers to cause a denial of service (integer overflow) or possibly have unspecified other impact via a crafted regular expression, as demonstrated by a JavaScript RegExp object encountered by Konqueror.

CVSS3: 9.8
nvd
больше 9 лет назад

PCRE before 8.38 mishandles the (?(<digits>) and (?(R<digits>) conditions, which allows remote attackers to cause a denial of service (integer overflow) or possibly have unspecified other impact via a crafted regular expression, as demonstrated by a JavaScript RegExp object encountered by Konqueror.

CVSS3: 9.8
debian
больше 9 лет назад

PCRE before 8.38 mishandles the (?(<digits>) and (?(R<digits>) conditi ...

CVSS3: 9.8
github
около 3 лет назад

PCRE before 8.38 mishandles the (?(<digits>) and (?(R<digits>) conditions, which allows remote attackers to cause a denial of service (integer overflow) or possibly have unspecified other impact via a crafted regular expression, as demonstrated by a JavaScript RegExp object encountered by Konqueror.

suse-cvrf
больше 8 лет назад

Security update for pcre

EPSS

Процентиль: 86%
0.03025
Низкий

4.3 Medium

CVSS2