The pcre_compile function in pcre_compile.c in PCRE before 8.38 mishandles certain [: nesting, which allows remote attackers to cause a denial of service (CPU consumption) or possibly have unspecified other impact via a crafted regular expression, as demonstrated by a JavaScript RegExp object encountered by Konqueror.
References
| Link | Resource |
|---|---|
| http://vcs.pcre.org/pcre/code/trunk/ChangeLog?view=markup | Broken Link |
| http://www.openwall.com/lists/oss-security/2015/11/29/1 | Mailing List Third Party Advisory |
| https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c05240731 | Third Party Advisory |
| http://www.oracle.com/technetwork/topics/security/linuxbulletinapr2016-2952096.html | Third Party Advisory |
| http://www.securityfocus.com/bid/82990 | Third Party Advisory VDB Entry |
| http://lists.fedoraproject.org/pipermail/package-announce/2016-January/174931.html | Mailing List Third Party Advisory |
| http://www-01.ibm.com/support/docview.wss?uid=isg3T1023886 | Third Party Advisory |
| https://bto.bluecoat.com/security-advisory/sa128 | Permissions Required |
| https://security.gentoo.org/glsa/201607-02 | Third Party Advisory |
| https://access.redhat.com/errata/RHSA-2016:1132 | Third Party Advisory |
| http://rhn.redhat.com/errata/RHSA-2016-2750.html | Third Party Advisory |
| http://rhn.redhat.com/errata/RHSA-2016-1025.html | Third Party Advisory |
Configurations
Configuration 1 (hide)
|
Configuration 2 (hide)
|
Configuration 3 (hide)
|
Configuration 4 (hide)
|
Information
Published : 2015-12-02 01:59
Updated : 2022-07-20 17:29
NVD link : CVE-2015-8391
Mitre link : CVE-2015-8391
JSON object : View
Products Affected
redhat
- enterprise_linux_server_tus
- enterprise_linux_desktop
- enterprise_linux_workstation
- enterprise_linux_server
- enterprise_linux_server_aus
- enterprise_linux_eus
oracle
- linux
fedoraproject
- fedora
pcre
- pcre
CWE
CWE-119
Improper Restriction of Operations within the Bounds of a Memory Buffer
