LWN.net Logo

pcre: denial of service

Package(s):pcre CVE #(s):CVE-2006-7225 CVE-2006-7226
Created:February 1, 2008 Updated:February 6, 2008
Description: From the CVE entries: Perl-Compatible Regular Expression (PCRE) library before 6.7 allows context-dependent attackers to cause a denial of service (error or crash) via a regular expression that involves a "malformed POSIX character class", as demonstrated via an invalid character after a [[ sequence. Perl-Compatible Regular Expression (PCRE) library before 6.7 does not properly calculate the compiled memory allocation for regular expressions that involve a quantified "subpattern containing a named recursion or subroutine reference," which allows context-dependent attackers to cause a denial of service (error or crash).
Alerts:
Mandriva MDVSA-2008:030 2008-01-31

(Log in to post comments)

pcre: denial of service

Posted Feb 7, 2008 18:07 UTC (Thu) by kreutzm (subscriber, #4700) [Link]

Debian Sarge and Etch are not vulnerable.

Copyright © 2008, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds
Powered by Rackspace Managed Hosting.