Lucene search

K
archlinuxArch LinuxASA-201603-18
HistoryMar 13, 2016 - 12:00 a.m.

pcre: arbitrary code execution

2016-03-1300:00:00
Arch Linux
lists.archlinux.org
26

0.016 Low

EPSS

Percentile

87.5%

PCRE library is prone to a vulnerability which leads to Heap Overflow.
During the compilation of a malformed regular expression, more data is
written on the malloced block than the expected size output by
compile_regex. Exploits with advanced Heap Fengshui techniques may allow
an attacker to execute arbitrary code in the context of the user running
the affected application.

OSVersionArchitecturePackageVersionFilename
anyanyanypcre< 8.38-3UNKNOWN