CVE-2005-2491
published 2005-08-23CVE-2005-2491: Integer overflow in pcre_compile.c in Perl Compatible Regular Expressions (PCRE) before 6.2, as used in multiple products such as Python, Ethereal, and PHP…
PriorityP335high7.5CVSS 2.0
AVNACLAuNCPIPAP
EPSS
4.34%
90.1th percentile
Integer overflow in pcre_compile.c in Perl Compatible Regular Expressions (PCRE) before 6.2, as used in multiple products such as Python, Ethereal, and PHP, allows attackers to execute arbitrary code via quantifier values in regular expressions, which leads to a heap-based buffer overflow.
Affected
11 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | gnumeric | < gnumeric 1.5.1-1 (bookworm) | gnumeric 1.5.1-1 (bookworm) |
| debian | goffice | < gnumeric 1.5.1-1 (bookworm) | gnumeric 1.5.1-1 (bookworm) |
| debian | pcre3 | < gnumeric 1.5.1-1 (bookworm) | gnumeric 1.5.1-1 (bookworm) |
| debian | vfu | < gnumeric 1.5.1-1 (bookworm) | gnumeric 1.5.1-1 (bookworm) |
| gnome | gnumeric | >= 0 < 1.5.1-1 | 1.5.1-1 |
| gnome | gnumeric | >= 0 < 1.5.1-1 | 1.5.1-1 |
| gnome | gnumeric | >= 0 < 1.5.1-1 | 1.5.1-1 |
| gnome | gnumeric | >= 0 < 1.5.1-1 | 1.5.1-1 |
| pcre | pcre | — | — |
| pcre | pcre | — | — |
| pcre | pcre | — | — |
CVSS provenance
nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
osv7.5HIGH
vendor_debian7.5LOW
vendor_redhat7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-h9j2-347v-3v58: Integer overflow in pcre_compile
ghsa_unreviewed·2022-05-03
CVE-2005-2491 [HIGH] GHSA-h9j2-347v-3v58: Integer overflow in pcre_compile
Integer overflow in pcre_compile.c in Perl Compatible Regular Expressions (PCRE) before 6.2, as used in multiple products such as Python, Ethereal, and PHP, allows attackers to execute arbitrary code via quantifier values in regular expressions, which leads to a heap-based buffer overflow.
OSV
CVE-2005-2491: Integer overflow in pcre_compile
osv·2005-08-23·CVSS 7.5
CVE-2005-2491 [HIGH] CVE-2005-2491: Integer overflow in pcre_compile
Integer overflow in pcre_compile.c in Perl Compatible Regular Expressions (PCRE) before 6.2, as used in multiple products such as Python, Ethereal, and PHP, allows attackers to execute arbitrary code via quantifier values in regular expressions, which leads to a heap-based buffer overflow.
Ubuntu
PCRE vulnerabilities
vendor_ubuntu·2005-08-31
CVE-2005-2491 PCRE vulnerabilities
Title: PCRE vulnerabilities
Summary: PCRE vulnerabilities
USN-173-1 fixed a buffer overflow vulnerability in the PCRE library.
However, it was found that the various python packages and gnumeric
contain static copies of the library code, so these packages need to
be updated as well.
In gnumeric this bug could be exploited to execute arbitrary code with
the privileges of the user if the user was tricked into opening a
specially crafted spreadsheet document.
In python, the impact depends on the particular application that uses
python's "re" (regular expression) module. In python server
applications that process unchecked arbitrary regular expressions with
the "re" module, this could potentially be exploited to remotely
execute arbitrary code with the privileges of the server.
Instructio
Ubuntu
PCRE vulnerability
vendor_ubuntu·2005-08-25
CVE-2005-2491 PCRE vulnerability
Title: PCRE vulnerability
Summary: PCRE vulnerability
USN-173-1 fixed a buffer overflow vulnerability in the PCRE library.
However, it was determined that this did not suffice to prevent all
possible overflows, so another update is necessary.
In addition, it was found that the Ubuntu 4.10 version of Apache 2
contains a static copy of the library code, so this package needs to
be updated as well. In Ubuntu 5.04, Apache 2 uses the external library
from the libpcre3 package.
Instructions: In general, a standard system update will make all the necessary changes.
Ubuntu
PCRE vulnerability
vendor_ubuntu·2005-08-24
CVE-2005-2491 PCRE vulnerability
Title: PCRE vulnerability
Summary: PCRE vulnerability
A buffer overflow has been discovered in the PCRE, a widely used
library that provides Perl compatible regular expressions. Specially
crafted regular expressions triggered a buffer overflow. On systems
that accept arbitrary regular expressions from untrusted users, this
could be exploited to execute arbitrary code with the privileges of
the application using the library.
Instructions: In general, a standard system update will make all the necessary changes.
Red Hat
pcre heap overflow
vendor_redhat·2005-08-01·CVSS 7.5
CVE-2005-2491 [HIGH] pcre heap overflow
pcre heap overflow
Integer overflow in pcre_compile.c in Perl Compatible Regular Expressions (PCRE) before 6.2, as used in multiple products such as Python, Ethereal, and PHP, allows attackers to execute arbitrary code via quantifier values in regular expressions, which leads to a heap-based buffer overflow.
Debian
CVE-2005-2491: gnumeric - Integer overflow in pcre_compile.c in Perl Compatible Regular Expressions (PCRE)...
vendor_debian·2005·CVSS 7.5
CVE-2005-2491 [HIGH] CVE-2005-2491: gnumeric - Integer overflow in pcre_compile.c in Perl Compatible Regular Expressions (PCRE)...
Integer overflow in pcre_compile.c in Perl Compatible Regular Expressions (PCRE) before 6.2, as used in multiple products such as Python, Ethereal, and PHP, allows attackers to execute arbitrary code via quantifier values in regular expressions, which leads to a heap-based buffer overflow.
Scope: local
bookworm: resolved (fixed in 1.5.1-1)
bullseye: resolved (fixed in 1.5.1-1)
forky: resolved (fixed in 1.5.1-1)
sid: resolved (fixed in 1.5.1-1)
trixie: resolved (fixed in 1.5.1-1)
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2005-2491 pcre heap overflow
bugzilla·2008-01-29·CVSS 7.5
CVE-2005-2491 [HIGH] CVE-2005-2491 pcre heap overflow
CVE-2005-2491 pcre heap overflow
Common Vulnerabilities and Exposures assigned an identifier CVE-2005-2491 to the following vulnerability:
Integer overflow in pcre_compile.c in Perl Compatible Regular Expressions (PCRE) before 6.2, as used in multiple products such as Python, Ethereal, and PHP, allows attackers to execute arbitrary code via quantifier values in regular expressions, which leads to a heap-based buffer overflow.
References:
http://support.avaya.com/elmodocs2/security/ASA-2005-216.pdf
http://support.avaya.com/elmodocs2/security/ASA-2005-223.pdf
http://support.avaya.com/elmodocs2/security/ASA-2006-081.htm
http://support.avaya.com/elmodocs2/security/ASA-2006-159.htm
http://docs.info.apple.com/article.html?artnum=302847
http://www.debian.org/security/2005/dsa-800
http://www.d
Bugzilla
CVE-2006-4980 repr unicode buffer overflow
bugzilla·2006-11-07·CVSS 7.5
CVE-2006-4980 [HIGH] CVE-2006-4980 repr unicode buffer overflow
CVE-2006-4980 repr unicode buffer overflow
A flaw was discovered in the way that the Python repr() function handled
UTF-32/UCS-4 strings. If an application written in Python used the repr()
function on untrusted data, this could lead to a denial of service or
possibly allow the execution of arbitrary code with the privileges of the
Python application. (CVE-2006-4980)
RH announcement: http://rhn.redhat.com/errata/RHSA-2006-0713.html
Looks like both FC3 and FC4 need patches.
Also, Bug #168318 has another possible python bug we need to investigate before
pushing a python update.
Discussion:
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1
I've created updated packages to fix this issue.
The FC3 package also includes a patch for CAN-2005-2491
see bug #168318
The patches are based off of
Bugzilla
CAN-2005-0089 CAN-2005-2491 python multiple security issues
bugzilla·2005-09-25
[MEDIUM] CAN-2005-0089 CAN-2005-2491 python multiple security issues
CAN-2005-0089 CAN-2005-2491 python multiple security issues
From Bugzilla Helper:
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 5.1; en-US; rv:1.7.12) Gecko/20050915 Firefox/1.0.7
Description of problem:
From CAN-2005-2491:
"Integer overflow in pcre_compile.c in Perl Compatible Regular
Expressions (PCRE) before 6.2, as used in multiple products, allows
attackers to execute arbitrary code via quantifier values in regular
expressions, which leads to a heap-based buffer overflow."
Version-Release number of selected component (if applicable):
How reproducible:
Didn't try
Additional info:
Per David Eisenstein
* pcre library (FL bug already opened: Bugzilla # 168516):
Ref: Bugzilla 166330 (RHEL) - CAN-2005-2491 PCRE heap overflow
Ref: RHSA-2005:761 - Moderate: pcre security update
Bugzilla
CVE-2005-2491 PCRE heap overflow
bugzilla·2005-08-19·CVSS 7.5
CVE-2005-2491 [HIGH] CVE-2005-2491 PCRE heap overflow
CVE-2005-2491 PCRE heap overflow
We need to determine if this issue affects Python; Python does contain it's own
version of pcre, but we didn't confirm if it used it's own version or the system
pcre library across all RHEL releases.
+++ This bug was initially created as a clone of Bug #166330 +++
PCRE 6.2 was released recently which included a fix for a heap buffer overflow.
PCRE is used by things such as Apache but only for configuration (therefore
making an exploit low severity). A number of packages also include PCRE code
internally, I'll be adding separate bugs for those that contain PCRE and do not
use system PCRE later.
Changelog states:
1. There was no test for integer overflow of quantifier values. A construction
such as {1111111111111111} would give undefined results. What is
ftp://ftp.sco.com/pub/updates/OpenServer/SCOSA-2006.10/SCOSA-2006.10.txtftp://patches.sgi.com/support/free/security/advisories/20060401-01-Uhttp://docs.info.apple.com/article.html?artnum=302847http://itrc.hp.com/service/cki/docDisplay.do?docId=c00786522http://lists.trustix.org/pipermail/tsl-announce/2005-October/000354.htmlhttp://marc.info/?l=bugtraq&m=112605112027335&w=2http://marc.info/?l=bugtraq&m=112606064317223&w=2http://marc.info/?l=bugtraq&m=130497311408250&w=2http://secunia.com/advisories/16502http://secunia.com/advisories/16679http://secunia.com/advisories/17252http://secunia.com/advisories/17813http://secunia.com/advisories/19072http://secunia.com/advisories/19193http://secunia.com/advisories/19532http://secunia.com/advisories/21522http://secunia.com/advisories/22691http://secunia.com/advisories/22875http://securityreason.com/securityalert/604http://securitytracker.com/id?1014744http://sunsolve.sun.com/search/document.do?assetkey=1-26-102198-1http://support.avaya.com/elmodocs2/security/ASA-2005-216.pdfhttp://support.avaya.com/elmodocs2/security/ASA-2005-223.pdfhttp://support.avaya.com/elmodocs2/security/ASA-2006-081.htmhttp://support.avaya.com/elmodocs2/security/ASA-2006-159.htmhttp://www.debian.org/security/2005/dsa-800http://www.debian.org/security/2005/dsa-817http://www.debian.org/security/2005/dsa-819http://www.debian.org/security/2005/dsa-821http://www.ethereal.com/appnotes/enpa-sa-00021.htmlhttp://www.gentoo.org/security/en/glsa/glsa-200508-17.xmlhttp://www.gentoo.org/security/en/glsa/glsa-200509-02.xmlhttp://www.gentoo.org/security/en/glsa/glsa-200509-08.xmlhttp://www.gentoo.org/security/en/glsa/glsa-200509-12.xmlhttp://www.gentoo.org/security/en/glsa/glsa-200509-19.xmlhttp://www.novell.com/linux/security/advisories/2005_48_pcre.htmlhttp://www.novell.com/linux/security/advisories/2005_49_php.htmlhttp://www.novell.com/linux/security/advisories/2005_52_apache2.htmlhttp://www.php.net/release_4_4_1.phphttp://www.redhat.com/support/errata/RHSA-2005-358.htmlhttp://www.redhat.com/support/errata/RHSA-2005-761.htmlhttp://www.redhat.com/support/errata/RHSA-2006-0197.htmlhttp://www.securityfocus.com/archive/1/427046/100/0/threadedhttp://www.securityfocus.com/archive/1/428138/100/0/threadedhttp://www.securityfocus.com/bid/14620http://www.securityfocus.com/bid/15647http://www.vupen.com/english/advisories/2005/1511http://www.vupen.com/english/advisories/2005/2659http://www.vupen.com/english/advisories/2006/0789http://www.vupen.com/english/advisories/2006/4320http://www.vupen.com/english/advisories/2006/4502https://lists.apache.org/thread.html/54a42d4b01968df1117cea77fc53d6beb931c0e05936ad02af93e9ac%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/5df9bfb86a3b054bb985a45ff9250b0332c9ecc181eec232489e7f79%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/r0276683d8e1e07153fc8642618830ac0ade85b9ae0dc7b07f63bb8fc%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/r2cb985de917e7da0848c440535f65a247754db8b2154a10089e4247b%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/r5001ecf3d6b2bdd0b732e527654248abb264f08390045d30709a92f6%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/r8828e649175df56f1f9e3919938ac7826128525426e2748f0ab62feb%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/r9e8622254184645bc963a1d47c5d47f6d5a36d6f080d8d2c43b2b142%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/r9f93cf6dde308d42a9c807784e8102600d0397f5f834890708bf6920%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/rafd145ba6cd0a4ced113a5823cdaff45aeb36eb09855b216401c66d6%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/rd65d8ba68ba17e7deedafbf5bb4899f2ae4dad781d21b931c2941ac3%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/re895fc1736d25c8cf57e102c871613b8aeec9ea26fd8a44e7942b5ab%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/rf6449464fd8b7437704c55f88361b66f12d5b5f90bcce66af4be4ba9%40%3Ccvs.httpd.apache.org%3Ehttps://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11516https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1496https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1659https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A735ftp://ftp.sco.com/pub/updates/OpenServer/SCOSA-2006.10/SCOSA-2006.10.txtftp://patches.sgi.com/support/free/security/advisories/20060401-01-Uhttp://docs.info.apple.com/article.html?artnum=302847http://itrc.hp.com/service/cki/docDisplay.do?docId=c00786522http://lists.trustix.org/pipermail/tsl-announce/2005-October/000354.htmlhttp://marc.info/?l=bugtraq&m=112605112027335&w=2http://marc.info/?l=bugtraq&m=112606064317223&w=2http://marc.info/?l=bugtraq&m=130497311408250&w=2http://secunia.com/advisories/16502http://secunia.com/advisories/16679http://secunia.com/advisories/17252http://secunia.com/advisories/17813http://secunia.com/advisories/19072http://secunia.com/advisories/19193http://secunia.com/advisories/19532http://secunia.com/advisories/21522http://secunia.com/advisories/22691http://secunia.com/advisories/22875http://securityreason.com/securityalert/604http://securitytracker.com/id?1014744http://sunsolve.sun.com/search/document.do?assetkey=1-26-102198-1http://support.avaya.com/elmodocs2/security/ASA-2005-216.pdfhttp://support.avaya.com/elmodocs2/security/ASA-2005-223.pdfhttp://support.avaya.com/elmodocs2/security/ASA-2006-081.htmhttp://support.avaya.com/elmodocs2/security/ASA-2006-159.htmhttp://www.debian.org/security/2005/dsa-800http://www.debian.org/security/2005/dsa-817http://www.debian.org/security/2005/dsa-819http://www.debian.org/security/2005/dsa-821http://www.ethereal.com/appnotes/enpa-sa-00021.htmlhttp://www.gentoo.org/security/en/glsa/glsa-200508-17.xmlhttp://www.gentoo.org/security/en/glsa/glsa-200509-02.xmlhttp://www.gentoo.org/security/en/glsa/glsa-200509-08.xml
+ 34 more references
2005-08-23
Published