Denial of Service Vulnerability in PCRE by Vendor PCRE
CVE-2015-8387

7.3HIGH

Key Information:

Vendor

Pcre

Vendor
CVE Published:
2 December 2015

What is CVE-2015-8387?

A critical flaw in the PCRE library prior to version 8.38 allows remote attackers to exploit improper handling of subroutine calls within regular expressions. This vulnerability can lead to a denial of service through integer overflow, potentially allowing attackers to disrupt application functionality. Notably, the issue can be triggered by crafted regular expression inputs, as demonstrated in situations like the JavaScript RegExp object in the Konqueror browser. Keeping your PCRE library updated is essential to mitigate this risk.

References

CVSS V3.1

Score:
7.3
Severity:
HIGH
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.