Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2015-5073

Опубликовано: 13 дек. 2016
Источник: ubuntu
Приоритет: low
EPSS Низкий
CVSS2: 6.4
CVSS3: 9.1

Описание

Heap-based buffer overflow in the find_fixedlength function in pcre_compile.c in PCRE before 8.38 allows remote attackers to cause a denial of service (crash) or obtain sensitive information from heap memory and possibly bypass the ASLR protection mechanism via a crafted regular expression with an excess closing parenthesis.

РелизСтатусПримечание
devel

not-affected

2:8.38-3
esm-infra-legacy/trusty

not-affected

1:8.31-2ubuntu2.1
precise

released

8.12-4ubuntu0.1
trusty

released

1:8.31-2ubuntu2.1
trusty/esm

not-affected

1:8.31-2ubuntu2.1
upstream

released

2:8.35-7
utopic

ignored

end of life
vivid

released

2:8.35-3.3ubuntu1.1
vivid/stable-phone-overlay

released

2:8.35-3.3ubuntu1.1
vivid/ubuntu-core

released

2:8.35-3.3ubuntu1.1

Показывать по

EPSS

Процентиль: 71%
0.00714
Низкий

6.4 Medium

CVSS2

9.1 Critical

CVSS3

Связанные уязвимости

redhat
около 10 лет назад

Heap-based buffer overflow in the find_fixedlength function in pcre_compile.c in PCRE before 8.38 allows remote attackers to cause a denial of service (crash) or obtain sensitive information from heap memory and possibly bypass the ASLR protection mechanism via a crafted regular expression with an excess closing parenthesis.

CVSS3: 9.1
nvd
больше 8 лет назад

Heap-based buffer overflow in the find_fixedlength function in pcre_compile.c in PCRE before 8.38 allows remote attackers to cause a denial of service (crash) or obtain sensitive information from heap memory and possibly bypass the ASLR protection mechanism via a crafted regular expression with an excess closing parenthesis.

CVSS3: 9.1
debian
больше 8 лет назад

Heap-based buffer overflow in the find_fixedlength function in pcre_co ...

CVSS3: 9.1
github
около 3 лет назад

Heap-based buffer overflow in the find_fixedlength function in pcre_compile.c in PCRE before 8.38 allows remote attackers to cause a denial of service (crash) or obtain sensitive information from heap memory and possibly bypass the ASLR protection mechanism via a crafted regular expression with an excess closing parenthesis.

oracle-oval
около 9 лет назад

ELSA-2016-1025: pcre security update (IMPORTANT)

EPSS

Процентиль: 71%
0.00714
Низкий

6.4 Medium

CVSS2

9.1 Critical

CVSS3