PT-2008-1088 · Pcre+1 · Pcre Library+1

·

CVE-2008-2371

·

Publicado

2008-07-07

·

Atualizado

2022-08-01

CVSS v2.0

7.5

Alta

VetorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions PCRE library versions prior to 7.7
Description The issue is related to a heap-based buffer overflow in the PCRE library, specifically in the pcre compile.c file. This allows context-dependent attackers to cause a denial of service or possibly execute arbitrary code via a specially crafted regular expression. The vulnerability can be exploited remotely, potentially leading to a violation of confidentiality, integrity, and availability of protected information.
Recommendations For PCRE library versions prior to 7.7, update to version 7.7 or later to resolve the issue. As a temporary workaround, consider restricting the use of the pcre compile() function until a patch is available. Avoid using complex regular expressions that begin with an option and contain multiple branches in the affected PCRE library versions.

Exploit

Correção

DoS

Memory Corruption

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2015-09343
CVE-2008-2371
DSA-1602-1
DTSA-145-1
HPSBUX02431
HPSBUX02465
OPENSUSE-SU-2024:10791-1

Produtos afetados

Hp-Ux
Pcre Library