Denial of Service Vulnerability in PCRE Library by Vendor
CVE-2015-2327

Currently unrated

Key Information:

Vendor

Pcre

Vendor
CVE Published:
2 December 2015

What is CVE-2015-2327?

The PCRE library prior to version 8.36 contains a vulnerability that improperly handles specific complex regular expression patterns, particularly those involving internal recursive back references. This mismanagement can lead to a denial of service condition due to segmentation faults triggered by crafted regular expressions. Attackers can exploit this flaw remotely, potentially impacting applications that rely on the PCRE library for regular expression processing.

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.