Buffer Overflow in PCRE Affects Multiple Products
CVE-2015-8380

Currently unrated

Key Information:

Vendor

Pcre

Vendor
CVE Published:
2 December 2015

What is CVE-2015-8380?

The pcre_exec function in the PCRE library versions prior to 8.38 encounters issues when handling specific patterns, particularly a // pattern combined with a \01 string. This can potentially lead to a heap-based buffer overflow, enabling remote attackers to execute crafted regular expressions that could result in denial of service. This vulnerability has been highlighted through various use cases, including a JavaScript RegExp object in the Konqueror browser. Users are advised to review and update their PCRE installations to mitigate any associated risks.

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.