Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2017-16231

Опубликовано: 01 нояб. 2017
Источник: redhat
CVSS3: 5.5
EPSS Низкий

Описание

In PCRE 8.41, after compiling, a pcretest load test PoC produces a crash overflow in the function match() in pcre_exec.c because of a self-recursive call. NOTE: third parties dispute the relevance of this report, noting that there are options that can be used to limit the amount of stack that is used

Отчет

Red Hat Product Security determined that this flaw was not a security vulnerability. See the Bugzilla link for more details.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 5pcreNot affected
Red Hat Enterprise Linux 6chromium-browserNot affected
Red Hat Enterprise Linux 6firefoxNot affected
Red Hat Enterprise Linux 6glib2Not affected
Red Hat Enterprise Linux 6pcreNot affected
Red Hat Enterprise Linux 6thunderbirdNot affected
Red Hat Enterprise Linux 7glib2Not affected
Red Hat Enterprise Linux 7pcreNot affected
Red Hat Enterprise Linux 7virtuoso-opensourceNot affected
Red Hat Enterprise Linux 8mingw-pcreNot affected

Показывать по

Дополнительная информация

Дефект:
CWE-119->CWE-400
https://bugzilla.redhat.com/show_bug.cgi?id=1700392pcre: self-recursive call in match() in pcre_exec.c leads to denial of service

EPSS

Процентиль: 27%
0.00094
Низкий

5.5 Medium

CVSS3

Связанные уязвимости

CVSS3: 5.5
ubuntu
почти 7 лет назад

In PCRE 8.41, after compiling, a pcretest load test PoC produces a crash overflow in the function match() in pcre_exec.c because of a self-recursive call. NOTE: third parties dispute the relevance of this report, noting that there are options that can be used to limit the amount of stack that is used

CVSS3: 5.5
nvd
почти 7 лет назад

In PCRE 8.41, after compiling, a pcretest load test PoC produces a crash overflow in the function match() in pcre_exec.c because of a self-recursive call. NOTE: third parties dispute the relevance of this report, noting that there are options that can be used to limit the amount of stack that is used

CVSS3: 5.5
debian
почти 7 лет назад

In PCRE 8.41, after compiling, a pcretest load test PoC produces a cra ...

CVSS3: 5.5
github
больше 3 лет назад

** DISPUTED ** In PCRE 8.41, after compiling, a pcretest load test PoC produces a crash overflow in the function match() in pcre_exec.c because of a self-recursive call. NOTE: third parties dispute the relevance of this report, noting that there are options that can be used to limit the amount of stack that is used.

EPSS

Процентиль: 27%
0.00094
Низкий

5.5 Medium

CVSS3