Lucene search

K
cve[email protected]CVE-2008-2371
HistoryJul 07, 2008 - 11:41 p.m.

CVE-2008-2371

2008-07-0723:41:00
CWE-787
web.nvd.nist.gov
83
3
cve-2008-2371
nvd
pcre
buffer overflow
denial of service
crash
arbitrary code
regular expression

7.5 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:P/I:P/A:P

9.2 High

AI Score

Confidence

High

0.004 Low

EPSS

Percentile

72.4%

Heap-based buffer overflow in pcre_compile.c in the Perl-Compatible Regular Expression (PCRE) library 7.7 allows context-dependent attackers to cause a denial of service (crash) or possibly execute arbitrary code via a regular expression that begins with an option and contains multiple branches.

Affected configurations

NVD
Node
pcrepcreMatch7.7
Node
phpphpRange5.2.0–5.2.7
Node
debiandebian_linuxMatch4.0
Node
canonicalubuntu_linuxMatch6.06
OR
canonicalubuntu_linuxMatch7.04
OR
canonicalubuntu_linuxMatch7.10
OR
canonicalubuntu_linuxMatch8.04-
OR
canonicalubuntu_linuxMatch9.10
Node
fedoraprojectfedoraMatch8
OR
fedoraprojectfedoraMatch9
Node
opensuseopensuseMatch10.3
CPENameOperatorVersion
pcre:pcrepcreeq7.7

References

Social References

More

7.5 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:P/I:P/A:P

9.2 High

AI Score

Confidence

High

0.004 Low

EPSS

Percentile

72.4%