Denial of Service Vulnerability in PCRE Software by Vendor
CVE-2015-8392

Currently unrated

Key Information:

Vendor

Pcre

Vendor
CVE Published:
2 December 2015

What is CVE-2015-8392?

The PCRE library prior to version 8.38 has a vulnerability that improperly handles certain instances of the (?| substring. This flaw can be exploited by remote attackers to trigger denial of service conditions, leading to unintended recursion and buffer overflow. The issue is exacerbated when a crafted regular expression is executed, as demonstrated by instances found in JavaScript regular expression objects. This vulnerability is linked to related issues identified in CVE-2015-8384 and CVE-2015-8395.

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.