Serve your customers, not your servers, with VERIO Linux VPS.
Full-access test-drive
here.
|
| Package(s): | pcre |
CVE #(s): | CVE-2006-7225
CVE-2006-7226
|
| Created: | February 1, 2008 |
Updated: | February 6, 2008 |
| Description: |
From the CVE entries: Perl-Compatible Regular Expression (PCRE) library
before 6.7 allows context-dependent attackers to cause a denial of service
(error or crash) via a regular expression that involves a "malformed POSIX
character class", as demonstrated via an invalid character after a [[
sequence. Perl-Compatible Regular Expression (PCRE) library before 6.7
does not properly calculate the compiled memory allocation for regular
expressions that involve a quantified "subpattern containing a named
recursion or subroutine reference," which allows context-dependent
attackers to cause a denial of service (error or crash). |
| Alerts: |
|
( Log in to post comments)
|