Denial of Service Vulnerability in PCRE from Vendor
CVE-2015-8384

Currently unrated

Key Information:

Vendor

Pcre

Vendor
CVE Published:
2 December 2015

What is CVE-2015-8384?

The vulnerability in PCRE prior to version 8.38 arises from the mishandling of specific regex patterns with recursive back references. This flaw can be exploited by remote attackers, potentially leading to a denial of service due to buffer overflow. Attackers may craft malicious regular expressions, as exhibited by certain JavaScript RegExp objects encountered in specific applications like Konqueror, posing significant risks in environments that utilize vulnerable versions of PCRE.

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.