Denial of Service Vulnerability in PCRE Affecting PHP
CVE-2017-6004
7.5HIGH
What is CVE-2017-6004?
A vulnerability exists in the compile_bracket_matchingpath function of the PCRE library which is bundled with PHP. This issue allows remote attackers to exploit crafted regular expressions, leading to out-of-bounds memory reads and potentially crashing the application. By manipulating the input regex, an attacker can trigger this flaw, resulting in a denial of service. It is essential for users of affected PHP versions to apply the necessary updates to mitigate this risk.
