Back to search
CVE-2015-3217
Published: Dec 13, 2016
Modified: Aug 6, 2024
PUBLISHED
Description
PCRE 7.8 and 8.32 through 8.37, and PCRE2 10.10 mishandle group empty matches, which might allow remote attackers to cause a denial of service (stack-based buffer overflow) via a crafted regular expression, as demonstrated by /^(?:(?(1)\\.|([^\\\\W_])?)+)+$/.
| Vendor | Product | Versions |
|---|---|---|
n/a | n/a | affected n/a |
References
RHSA-2016:1132
vendor-advisory
x_refsource_REDHAT
http://vcs.pcre.org/pcre?view=revision&revision=1566
x_refsource_CONFIRM
https://bugs.exim.org/show_bug.cgi?id=1638
x_refsource_CONFIRM
[oss-security] 20150603 CVE-2015-3217: PCRE Library Call Stack Overflow Vulnerability in match()
mailing-list
x_refsource_MLIST
http://www-01.ibm.com/support/docview.wss?uid=isg3T1023886
x_refsource_CONFIRM
RHSA-2016:1025
vendor-advisory
x_refsource_REDHAT
RHSA-2016:2750
vendor-advisory
x_refsource_REDHAT
https://bugzilla.redhat.com/show_bug.cgi?id=1228283
x_refsource_CONFIRM
75018
vdb-entry
x_refsource_BID
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now