CVE-2015-5073
Heap-based buffer overflow in the find_fixedlength function in pcre_compile.c in PCRE before 8.38 allows remote attackers to cause a denial of service (crash) or obtain sensitive information from heap memory and possibly bypass the ASLR protection…
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (7.67%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
Heap-based buffer overflow in the find_fixedlength function in pcre_compile.c in PCRE before 8.38 allows remote attackers to cause a denial of service (crash) or obtain sensitive information from heap memory and possibly bypass the ASLR protection mechanism via a crafted regular expression with an excess closing parenthesis.
- CVSS 3.0
- 9.1 CRITICALCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H
- EPSS
- 7.67% probability · 94th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-119, CWE-200
- Affected
- ibm/powerkvm · pcre/pcre
- Source
- cve@mitre.org
References
- http://rhn.redhat.com/errata/RHSA-2016-1025.html
- http://rhn.redhat.com/errata/RHSA-2016-2750.html
- http://vcs.pcre.org/pcre/code/trunk/ChangeLog?revision=1609&view=markupVendor Advisory
- http://vcs.pcre.org/pcre?view=revision&revision=1571Exploit, Vendor Advisory
- http://www-01.ibm.com/support/docview.wss?uid=isg3T1023886Third Party Advisory
- http://www.openwall.com/lists/oss-security/2015/06/26/1Mailing List
- http://www.openwall.com/lists/oss-security/2015/06/26/3Mailing List
- http://www.oracle.com/technetwork/topics/security/linuxbulletinapr2016-2952096.html
- http://www.securityfocus.com/bid/75430Third Party Advisory, VDB Entry
- http://www.securitytracker.com/id/1033154Third Party Advisory, VDB Entry
- https://access.redhat.com/errata/RHSA-2016:1132
- https://bugs.exim.org/show_bug.cgi?id=1651Exploit
- https://security.gentoo.org/glsa/201607-02
- http://rhn.redhat.com/errata/RHSA-2016-1025.html
- http://rhn.redhat.com/errata/RHSA-2016-2750.html
- http://vcs.pcre.org/pcre/code/trunk/ChangeLog?revision=1609&view=markupVendor Advisory
- http://vcs.pcre.org/pcre?view=revision&revision=1571Exploit, Vendor Advisory
- http://www-01.ibm.com/support/docview.wss?uid=isg3T1023886Third Party Advisory
- http://www.openwall.com/lists/oss-security/2015/06/26/1Mailing List
- http://www.openwall.com/lists/oss-security/2015/06/26/3Mailing List
- http://www.oracle.com/technetwork/topics/security/linuxbulletinapr2016-2952096.html
- http://www.securityfocus.com/bid/75430Third Party Advisory, VDB Entry
- http://www.securitytracker.com/id/1033154Third Party Advisory, VDB Entry
- https://access.redhat.com/errata/RHSA-2016:1132
- https://bugs.exim.org/show_bug.cgi?id=1651Exploit
- https://security.gentoo.org/glsa/201607-02
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.