CVSS2
Attack Vector
NETWORK
Attack Complexity
MEDIUM
Authentication
NONE
Confidentiality Impact
NONE
Integrity Impact
NONE
Availability Impact
PARTIAL
AV:N/AC:M/Au:N/C:N/I:N/A:P
EPSS
Percentile
68.0%
Perl-Compatible Regular Expression (PCRE) library before 6.2 does not
properly count the number of named capturing subpatterns, which allows
context-dependent attackers to cause a denial of service (crash) via a
regular expression with a large number of named subpatterns, which triggers
a buffer overflow. NOTE: this issue was originally subsumed by
CVE-2006-7224, but that CVE has been REJECTED and split.