CVE-2007-4767Infinite Loop in Pcre

8 documents7 sources
Severity
5.0MEDIUMNVD
EPSS
2.0%
top 16.49%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedNov 7
Latest updateMay 1

Description

Perl-Compatible Regular Expression (PCRE) library before 7.3 does not properly compute the length of (1) a \p sequence, (2) a \P sequence, or (3) a \P{x} sequence, which allows context-dependent attackers to cause a denial of service (infinite loop or crash) or execute arbitrary code.

CVSS vector

AV:N/AC:L/C:N/I:N/A:PExploitability: 10.0 | Impact: 2.9

Affected Packages3 packages

debiandebian/pcre3< glib2.0 2.14.3-1 (bookworm)
NVDpcre/pcre6.0+2
debiandebian/glib2.0< glib2.0 2.14.3-1 (bookworm)

🔴Vulnerability Details

2
GHSA
GHSA-9cw9-v886-c24m: Perl-Compatible Regular Expression (PCRE) library before 72022-05-01
OSV
CVE-2007-4767: Perl-Compatible Regular Expression (PCRE) library before 72007-11-07

📋Vendor Advisories

3
Ubuntu
PCRE vulnerabilities2007-11-27
Red Hat
: pcre < 7.3 \p, \P, \P{x] length calculation issue2007-11-05
Debian
CVE-2007-4767: glib2.0 - Perl-Compatible Regular Expression (PCRE) library before 7.3 does not properly c...2007

💬Community

2
Bugzilla
CVE-2007-4767: pcre < 7.3 \p, \P, \P{x] length calculation issue2007-11-20
Bugzilla
Multiple PCRE flaws2007-09-26