|
|
Log in / Subscribe / Register

pcre: denial of service

Package(s):pcre CVE #(s):CVE-2016-1283
Created:March 2, 2016 Updated:June 21, 2016
Description: From the CVE entry:

The pcre_compile2 function in pcre_compile.c in PCRE 8.38 mishandles the /((?:F?+(?:^(?(R)a+\"){99}-))(?J)(?'R'(?'R'<((?'RR'(?'R'\){97)?J)?J)(?'R'(?'R'\){99|(:(?|(?'R')(\k'R')|((?'R')))H'R'R)(H'R))))))/ pattern and related patterns with named subgroups, which allows remote attackers to cause a denial of service (heap-based buffer overflow) or possibly have unspecified other impact via a crafted regular expression, as demonstrated by a JavaScript RegExp object encountered by Konqueror.

Alerts:
openSUSE openSUSE-SU-2016:2805-1 pcre 2016-11-15
Gentoo 201607-02 libpcre 2016-07-09
Slackware SSA:2016-172-02 pcre 2016-06-20
Red Hat RHSA-2016:1132-01 rh-mariadb100-mariadb 2016-05-26
Mageia MGASA-2016-0204 pcre 2016-05-24
openSUSE openSUSE-SU-2016:3099-1 pcre 2016-12-12
Ubuntu USN-2943-1 pcre3 2016-03-29
Fedora FEDORA-2016-f5af8e27ce pcre 2016-03-16
Arch Linux ASA-201603-18 pcre 2016-03-13
Fedora FEDORA-2016-65833b5dbc pcre 2016-03-02

to post comments


Copyright © 2026, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds