CVE-2014-8964 — Improper Restriction of Operations within the Bounds of a Memory Buffer in Pcre
CWE-119 — Improper Restriction of Operations within the Bounds of a Memory Buffer11 documents8 sources
Severity
5.0MEDIUMNVD
EPSS
2.1%
top 16.07%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedDec 16
Latest updateMay 17
Description
Heap-based buffer overflow in PCRE 8.36 and earlier allows remote attackers to cause a denial of service (crash) or have other unspecified impact via a crafted regular expression, related to an assertion that allows zero repeats.
CVSS vector
AV:N/AC:L/C:N/I:N/A:PExploitability: 10.0 | Impact: 2.9
Affected Packages7 packages
Also affects: Fedora 19, 20, 21, Enterprise Linux 7.3, 7.4, 7.5, 7.6, 7.7