Description
The compile_branch function in PCRE before 8.37 allows context-dependent attackers to compile incorrect code, cause a denial of service (out-of-bounds heap read and crash), or possibly have other unspecified impact via a regular expression with a group containing a forward reference repeated a large number of times within a repeated outer group that has a zero minimum quantifier.
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2015-2418 | The compile_branch function in PCRE before 8.37 allows context-dependent attackers to compile incorrect code, cause a denial of service (out-of-bounds heap read and crash), or possibly have other unspecified impact via a regular expression with a group containing a forward reference repeated a large number of times within a repeated outer group that has a zero minimum quantifier. |
Ubuntu USN |
USN-2694-1 | PCRE vulnerabilities |
Ubuntu USN |
USN-2943-1 | PCRE vulnerabilities |
References
History
No history.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-08-06T05:10:15.978Z
Reserved: 2015-03-18T00:00:00.000Z
Link: CVE-2015-2325
No data.
Status : Modified
Published: 2020-01-14T17:15:12.080
Modified: 2024-11-21T02:27:13.130
Link: CVE-2015-2325
OpenCVE Enrichment
No data.
EUVD
Ubuntu USN