Lucene search

K
cveMitreCVE-2007-1660
HistoryNov 07, 2007 - 11:46 p.m.

CVE-2007-1660

2007-11-0723:46:00
CWE-119
mitre
web.nvd.nist.gov
51
pcre
buffer overflow
cve-2007-1660
denial of service
nvd

CVSS2

6.8

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:M/Au:N/C:P/I:P/A:P

AI Score

10

Confidence

High

EPSS

0.04

Percentile

92.1%

Perl-Compatible Regular Expression (PCRE) library before 7.0 does not properly calculate sizes for unspecified “multiple forms of character class”, which triggers a buffer overflow that allows context-dependent attackers to cause a denial of service (crash) and possibly execute arbitrary code.

Affected configurations

Nvd
Node
pcrepcreRange6.9
VendorProductVersionCPE
pcrepcrecpe:/a:pcre:pcre::::

References

CVSS2

6.8

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:M/Au:N/C:P/I:P/A:P

AI Score

10

Confidence

High

EPSS

0.04

Percentile

92.1%