Buffer Overflow in PCRE Affects Multiple Products
CVE-2015-8380
Currently unrated
Key Information:
- Vendor
Pcre
- Vendor
- CVE Published:
- 2 December 2015
What is CVE-2015-8380?
The pcre_exec function in the PCRE library versions prior to 8.38 encounters issues when handling specific patterns, particularly a // pattern combined with a \01 string. This can potentially lead to a heap-based buffer overflow, enabling remote attackers to execute crafted regular expressions that could result in denial of service. This vulnerability has been highlighted through various use cases, including a JavaScript RegExp object in the Konqueror browser. Users are advised to review and update their PCRE installations to mitigate any associated risks.
