Information Disclosure Vulnerability in PCRE
CVE-2015-8393

7.5HIGH

Key Information:

Vendor

Pcre

Vendor
CVE Published:
2 December 2015

What is CVE-2015-8393?

The pcregrep tool in PCRE versions prior to 8.38 has a flaw that mishandles the -q option when processing binary files. This vulnerability could potentially be exploited by remote attackers who craft specific files, allowing them to access sensitive information sent through standard output. The situation is exacerbated when this command is executed in a CGI environment, presenting risks to users who rely on these functionalities without proper sanitization or validation of the input files.

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.