CVE-2007-4766Integer Overflow or Wraparound in Pcre

Severity
7.5HIGHNVD
EPSS
3.9%
top 11.77%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedNov 7
Latest updateMay 1

Description

Multiple integer overflows in Perl-Compatible Regular Expression (PCRE) library before 7.3 allow context-dependent attackers to cause a denial of service (crash) or execute arbitrary code via unspecified escape (backslash) sequences.

CVSS vector

AV:N/AC:L/C:P/I:P/A:PExploitability: 10.0 | Impact: 6.4

Affected Packages3 packages

debiandebian/pcre3< glib2.0 2.14.3-1 (bookworm)
NVDpcre/pcre7.3
debiandebian/glib2.0< glib2.0 2.14.3-1 (bookworm)

Patches

🔴Vulnerability Details

2
GHSA
GHSA-ppf2-g285-2xj9: Multiple integer overflows in Perl-Compatible Regular Expression (PCRE) library before 72022-05-01
OSV
CVE-2007-4766: Multiple integer overflows in Perl-Compatible Regular Expression (PCRE) library before 72007-11-07

📋Vendor Advisories

3
Ubuntu
PCRE vulnerabilities2007-11-27
Red Hat
: pcre < 7.3 integer overflows2007-11-05
Debian
CVE-2007-4766: glib2.0 - Multiple integer overflows in Perl-Compatible Regular Expression (PCRE) library ...2007

💬Community

2
Bugzilla
CVE-2007-4766: pcre < 7.3 integer overflows2007-11-20
Bugzilla
Multiple PCRE flaws2007-09-26