Heap Overflow Vulnerability in PCRE and PCRE2 Libraries
CVE-2015-8381

Currently unrated

Key Information:

Vendor

Pcre

Vendor
CVE Published:
2 December 2015

What is CVE-2015-8381?

The heap-based buffer overflow vulnerability in the PCRE and PCRE2 libraries is triggered by specific crafted regular expressions that misuse group references. Attackers can exploit this flaw to cause a denial of service or potentially other unspecified impacts. This vulnerability affects PCRE versions prior to 8.38 and PCRE2 versions before 10.2x, impacting applications that rely on these libraries for regex processing, such as certain web browsers and other software components.

References

EPSS Score

5% chance of being exploited in the next 30 days.

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.