Denial of Service Vulnerability in PCRE by Moonsoft
CVE-2015-8395

Currently unrated

Key Information:

Vendor

Pcre

Vendor
CVE Published:
2 December 2015

What is CVE-2015-8395?

The vulnerability in PCRE prior to version 8.38 allows remote attackers to exploit mishandled references, potentially resulting in a denial of service. This issue can manifest through crafted regular expressions, as illustrated by scenarios involving JavaScript RegExp implementations in browsers like Konqueror. The exploitation even aligns with previously linked vulnerabilities, indicating a broader concern within the software's handling of regular expressions. Users are strongly advised to upgrade to the latest version to mitigate these risks.

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.