Lucene search

K
f5F5F5:K17331
HistorySep 29, 2015 - 12:00 a.m.

K17331 : PCRE library vulnerability CVE-2015-5073

2015-09-2900:00:00
my.f5.com
11

7.6 High

AI Score

Confidence

Low

0.031 Low

EPSS

Percentile

91.1%

Security Advisory Description

Heap-based buffer overflow in the find_fixedlength function in pcre_compile.c in PCRE before 8.38 allows remote attackers to cause a denial of service (crash) or obtain sensitive information from heap memory and possibly bypass the ASLR protection mechanism via a crafted regular expression with an excess closing parenthesis. (CVE-2015-5073)
Impact
A local, authenticated attacker may be able to provide malicious input in the configuration to exploit this vulnerability. There is no data plane exposure to this issue.