Denial of Service Vulnerability in PCRE Software by Vendor
CVE-2015-8392
Currently unrated
Key Information:
- Vendor
Pcre
- Vendor
- CVE Published:
- 2 December 2015
What is CVE-2015-8392?
The PCRE library prior to version 8.38 has a vulnerability that improperly handles certain instances of the (?| substring. This flaw can be exploited by remote attackers to trigger denial of service conditions, leading to unintended recursion and buffer overflow. The issue is exacerbated when a crafted regular expression is executed, as demonstrated by instances found in JavaScript regular expression objects. This vulnerability is linked to related issues identified in CVE-2015-8384 and CVE-2015-8395.
