cbcvebase.
CVE-2007-4768
published 2007-11-07

CVE-2007-4768: Heap-based buffer overflow in Perl-Compatible Regular Expression (PCRE) library before 7.3 allows context-dependent attackers to execute arbitrary code via a…

PriorityP334medium6.8CVSS 2.0
AVNACMAuNCPIPAP
EPSS
4.10%
89.6th percentile
Heap-based buffer overflow in Perl-Compatible Regular Expression (PCRE) library before 7.3 allows context-dependent attackers to execute arbitrary code via a singleton Unicode sequence in a character class in a regex pattern, which is incorrectly optimized.

Affected

5 ranges
VendorProductVersion rangeFixed in
debianglib2.0< glib2.0 2.14.3-1 (bookworm)glib2.0 2.14.3-1 (bookworm)
debianpcre3< glib2.0 2.14.3-1 (bookworm)glib2.0 2.14.3-1 (bookworm)
pcrepcre<= 6.0
pcrepcre<= 6.1
pcrepcre<= 7.3

CVSS provenance

nvdv2.06.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
osv6.8MEDIUM
vendor_debian6.8LOW
vendor_redhat6.8MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.