Information Disclosure and Denial of Service Risk in PCRE by Vendor
CVE-2015-8382

Currently unrated

Key Information:

Vendor

Pcre

Vendor
CVE Published:
2 December 2015

What is CVE-2015-8382?

The PCRE library before version 8.37 contains a flaw in the match function of pcre_exec.c that mismanages certain regular expression patterns. This security issue can lead to the disclosure of sensitive information from process memory and may also result in a denial of service, causing crashes due to partially initialized memory. Affected systems are vulnerable when processing crafted regular expressions, which could potentially be exploited by remote attackers.

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.