Lucene search

K
cveRedhatCVE-2006-7230
HistoryNov 15, 2007 - 7:46 p.m.

CVE-2006-7230

2007-11-1519:46:00
CWE-189
redhat
web.nvd.nist.gov
43
cve-2006-7230
perl-compatible regular expression
pcre library
denial of service
memory calculation vulnerability
nvd
security
vulnerability

CVSS2

4.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

PARTIAL

AV:N/AC:M/Au:N/C:N/I:N/A:P

AI Score

6

Confidence

Low

EPSS

0.024

Percentile

90.0%

Perl-Compatible Regular Expression (PCRE) library before 7.0 does not properly calculate the amount of memory needed for a compiled regular expression pattern when the (1) -x or (2) -i UTF-8 options change within the pattern, which allows context-dependent attackers to cause a denial of service (PCRE or glibc crash) via crafted regular expressions.

Affected configurations

Nvd
Node
pcrepcreRange6.9
VendorProductVersionCPE
pcrepcrecpe:/a:pcre:pcre::::

References

CVSS2

4.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

PARTIAL

AV:N/AC:M/Au:N/C:N/I:N/A:P

AI Score

6

Confidence

Low

EPSS

0.024

Percentile

90.0%