CVE-2008-2371
published 2008-07-07CVE-2008-2371: Heap-based buffer overflow in pcre_compile.c in the Perl-Compatible Regular Expression (PCRE) library 7.7 allows context-dependent attackers to cause a denial…
PriorityP339high7.5CVSS 2.0
AVNACLAuNCPIPAP
EPSS
6.73%
93.2th percentile
Heap-based buffer overflow in pcre_compile.c in the Perl-Compatible Regular Expression (PCRE) library 7.7 allows context-dependent attackers to cause a denial of service (crash) or possibly execute arbitrary code via a regular expression that begins with an option and contains multiple branches.
Affected
12 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| debian | debian_linux | — | — |
| debian | pcre3 | < pcre3 7.6-2.1 (bookworm) | pcre3 7.6-2.1 (bookworm) |
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
| opensuse | opensuse | — | — |
| pcre | pcre | — | — |
| php | php | 5.2.0 – 5.2.7 | — |
CVSS provenance
nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
osv7.5HIGH
vendor_debian7.5MEDIUM
vendor_redhat7.5HIGH
vendor_ubuntu5.0MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
Erlang vulnerability
vendor_ubuntu·2010-04-09
CVE-2008-2371 Erlang vulnerability
Title: Erlang vulnerability
Summary: Erlang vulnerability
USN-624-1 fixed a vulnerability in PCRE. This update provides the
corresponding update for Erlang.
Original advisory details:
Tavis Ormandy discovered that the PCRE library did not correctly handle
certain in-pattern options. An attacker could cause applications linked
against pcre3 to crash, leading to a denial of service.
Instructions: In general, a standard system upgrade is sufficient to effect the
necessary changes.
Ubuntu
PHP vulnerabilities
vendor_ubuntu·2008-07-23·CVSS 5.0
CVE-2007-4782 [MEDIUM] PHP vulnerabilities
Title: PHP vulnerabilities
Summary: PHP vulnerabilities
It was discovered that PHP did not properly check the length of the
string parameter to the fnmatch function. An attacker could cause a
denial of service in the PHP interpreter if a script passed untrusted
input to the fnmatch function. (CVE-2007-4782)
Maksymilian Arciemowicz discovered a flaw in the cURL library that
allowed safe_mode and open_basedir restrictions to be bypassed. If a
PHP application were tricked into processing a bad file:// request,
an attacker could read arbitrary files. (CVE-2007-4850)
Rasmus Lerdorf discovered that the htmlentities and htmlspecialchars
functions did not correctly stop when handling partial multibyte
sequences. A remote attacker could exploit this to read certain areas
of memory, possibly gai
Ubuntu
PCRE vulnerability
vendor_ubuntu·2008-07-15
CVE-2008-2371 PCRE vulnerability
Title: PCRE vulnerability
Summary: PCRE vulnerability
Tavis Ormandy discovered that the PCRE library did not correctly handle
certain in-pattern options. An attacker could cause applications linked
against pcre3 to crash, leading to a denial of service.
Instructions: In general, a standard system upgrade is sufficient to effect the
necessary changes.
Red Hat
pcre: heap overflow caused by incorrect option handling
vendor_redhat·2008-06-26·CVSS 7.5
CVE-2008-2371 [HIGH] pcre: heap overflow caused by incorrect option handling
pcre: heap overflow caused by incorrect option handling
Heap-based buffer overflow in pcre_compile.c in the Perl-Compatible Regular Expression (PCRE) library 7.7 allows context-dependent attackers to cause a denial of service (crash) or possibly execute arbitrary code via a regular expression that begins with an option and contains multiple branches.
Statement: Not vulnerable. This issue did not affect the versions of PCRE as shipped with Red Hat Enterprise Linux 2.1, 3, 4, or 5.
Debian
CVE-2008-2371: pcre3 - Heap-based buffer overflow in pcre_compile.c in the Perl-Compatible Regular Expr...
vendor_debian·2008·CVSS 7.5
CVE-2008-2371 [HIGH] CVE-2008-2371: pcre3 - Heap-based buffer overflow in pcre_compile.c in the Perl-Compatible Regular Expr...
Heap-based buffer overflow in pcre_compile.c in the Perl-Compatible Regular Expression (PCRE) library 7.7 allows context-dependent attackers to cause a denial of service (crash) or possibly execute arbitrary code via a regular expression that begins with an option and contains multiple branches.
Scope: local
bookworm: resolved (fixed in 7.6-2.1)
bullseye: resolved (fixed in 7.6-2.1)
GHSA
GHSA-853v-4rcq-pjpw: Heap-based buffer overflow in pcre_compile
ghsa_unreviewed·2022-05-01
CVE-2008-2371 [HIGH] CWE-119 GHSA-853v-4rcq-pjpw: Heap-based buffer overflow in pcre_compile
Heap-based buffer overflow in pcre_compile.c in the Perl-Compatible Regular Expression (PCRE) library 7.7 allows context-dependent attackers to cause a denial of service (crash) or possibly execute arbitrary code via a regular expression that begins with an option and contains multiple branches.
OSV
CVE-2008-2371: Heap-based buffer overflow in pcre_compile
osv·2008-07-07·CVSS 7.5
CVE-2008-2371 [HIGH] CVE-2008-2371: Heap-based buffer overflow in pcre_compile
Heap-based buffer overflow in pcre_compile.c in the Perl-Compatible Regular Expression (PCRE) library 7.7 allows context-dependent attackers to cause a denial of service (crash) or possibly execute arbitrary code via a regular expression that begins with an option and contains multiple branches.
No detection rules found.
No public exploits indexed.
http://bugs.gentoo.org/show_bug.cgi?id=228091http://ftp.gnome.org/pub/GNOME/sources/glib/2.16/glib-2.16.4.changeshttp://lists.apple.com/archives/security-announce/2008/Oct/msg00001.htmlhttp://lists.apple.com/archives/security-announce/2009/May/msg00002.htmlhttp://lists.opensuse.org/opensuse-security-announce/2008-07/msg00001.htmlhttp://marc.info/?l=bugtraq&m=124654546101607&w=2http://marc.info/?l=bugtraq&m=125631037611762&w=2http://secunia.com/advisories/30916http://secunia.com/advisories/30944http://secunia.com/advisories/30945http://secunia.com/advisories/30958http://secunia.com/advisories/30961http://secunia.com/advisories/30967http://secunia.com/advisories/30972http://secunia.com/advisories/30990http://secunia.com/advisories/31200http://secunia.com/advisories/32222http://secunia.com/advisories/32454http://secunia.com/advisories/32746http://secunia.com/advisories/35074http://secunia.com/advisories/35650http://secunia.com/advisories/39300http://security.gentoo.org/glsa/glsa-200811-05.xmlhttp://support.apple.com/kb/HT3216http://support.apple.com/kb/HT3549http://ubuntu.com/usn/usn-624-2http://wiki.rpath.com/wiki/Advisories:rPSA-2008-0305http://www.debian.org/security/2008/dsa-1602http://www.gentoo.org/security/en/glsa/glsa-200807-03.xmlhttp://www.mandriva.com/security/advisories?name=MDVSA-2008:147http://www.mandriva.com/security/advisories?name=MDVSA-2009:023http://www.securityfocus.com/archive/1/497828/100/0/threadedhttp://www.securityfocus.com/bid/30087http://www.securityfocus.com/bid/31681http://www.ubuntu.com/usn/usn-624-1http://www.ubuntu.com/usn/usn-628-1http://www.us-cert.gov/cas/techalerts/TA09-133A.htmlhttp://www.vupen.com/english/advisories/2008/2005http://www.vupen.com/english/advisories/2008/2006http://www.vupen.com/english/advisories/2008/2336http://www.vupen.com/english/advisories/2008/2780http://www.vupen.com/english/advisories/2009/1297http://www.vupen.com/english/advisories/2010/0833https://www.redhat.com/archives/fedora-package-announce/2008-July/msg00105.htmlhttps://www.redhat.com/archives/fedora-package-announce/2008-July/msg00123.htmlhttp://bugs.gentoo.org/show_bug.cgi?id=228091http://ftp.gnome.org/pub/GNOME/sources/glib/2.16/glib-2.16.4.changeshttp://lists.apple.com/archives/security-announce/2008/Oct/msg00001.htmlhttp://lists.apple.com/archives/security-announce/2009/May/msg00002.htmlhttp://lists.opensuse.org/opensuse-security-announce/2008-07/msg00001.htmlhttp://marc.info/?l=bugtraq&m=124654546101607&w=2http://marc.info/?l=bugtraq&m=125631037611762&w=2http://secunia.com/advisories/30916http://secunia.com/advisories/30944http://secunia.com/advisories/30945http://secunia.com/advisories/30958http://secunia.com/advisories/30961http://secunia.com/advisories/30967http://secunia.com/advisories/30972http://secunia.com/advisories/30990http://secunia.com/advisories/31200http://secunia.com/advisories/32222http://secunia.com/advisories/32454http://secunia.com/advisories/32746http://secunia.com/advisories/35074http://secunia.com/advisories/35650http://secunia.com/advisories/39300http://security.gentoo.org/glsa/glsa-200811-05.xmlhttp://support.apple.com/kb/HT3216http://support.apple.com/kb/HT3549http://ubuntu.com/usn/usn-624-2http://wiki.rpath.com/wiki/Advisories:rPSA-2008-0305http://www.debian.org/security/2008/dsa-1602http://www.gentoo.org/security/en/glsa/glsa-200807-03.xmlhttp://www.mandriva.com/security/advisories?name=MDVSA-2008:147http://www.mandriva.com/security/advisories?name=MDVSA-2009:023http://www.securityfocus.com/archive/1/497828/100/0/threadedhttp://www.securityfocus.com/bid/30087http://www.securityfocus.com/bid/31681http://www.ubuntu.com/usn/usn-624-1http://www.ubuntu.com/usn/usn-628-1http://www.us-cert.gov/cas/techalerts/TA09-133A.htmlhttp://www.vupen.com/english/advisories/2008/2005http://www.vupen.com/english/advisories/2008/2006http://www.vupen.com/english/advisories/2008/2336http://www.vupen.com/english/advisories/2008/2780http://www.vupen.com/english/advisories/2009/1297http://www.vupen.com/english/advisories/2010/0833https://www.redhat.com/archives/fedora-package-announce/2008-July/msg00105.htmlhttps://www.redhat.com/archives/fedora-package-announce/2008-July/msg00123.html
2008-07-07
Published