Stack-Based Buffer Overflow in PCRE Library Affects Multiple Applications
CVE-2017-7245

7.8HIGH

Key Information:

Vendor

Pcre

Status
Vendor
CVE Published:
23 March 2017

What is CVE-2017-7245?

The vulnerability in the PCRE library arises from a stack-based buffer overflow in the pcre32_copy_substring function within the pcre_get.c file. This flaw allows remote attackers to exploit crafted files to cause a denial of service, potentially leading to unexpected behavior in the affected applications. It is essential for organizations utilizing versions of the PCRE library to apply the necessary patches to mitigate the risk of exploitation.

References

CVSS V3.1

Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.