CVE-2014-8964Improper Restriction of Operations within the Bounds of a Memory Buffer in Pcre

Severity
5.0MEDIUMNVD
EPSS
2.1%
top 16.07%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedDec 16
Latest updateMay 17

Description

Heap-based buffer overflow in PCRE 8.36 and earlier allows remote attackers to cause a denial of service (crash) or have other unspecified impact via a crafted regular expression, related to an assertion that allows zero repeats.

CVSS vector

AV:N/AC:L/C:N/I:N/A:PExploitability: 10.0 | Impact: 2.9

Affected Packages7 packages

NVDpcre/pcre8.36
NVDmariadb/mariadb10.0.010.0.18
NVDoracle/solaris11.2
NVDopensuse/opensuse13.1, 13.2+1

Also affects: Fedora 19, 20, 21, Enterprise Linux 7.3, 7.4, 7.5, 7.6, 7.7

🔴Vulnerability Details

4
GHSA
GHSA-86jv-65cg-v7gc: Heap-based buffer overflow in PCRE 82022-05-17
OSV
pcre3 vulnerabilities2015-07-29
OSV
CVE-2014-8964: Heap-based buffer overflow in PCRE 82014-12-16
CVEList
CVE-2014-8964: Heap-based buffer overflow in PCRE 82014-12-16

📋Vendor Advisories

3
Ubuntu
PCRE vulnerabilities2015-07-29
Red Hat
pcre: incorrect handling of zero-repeat assertion conditions2014-11-18
Debian
CVE-2014-8964: pcre3 - Heap-based buffer overflow in PCRE 8.36 and earlier allows remote attackers to c...2014

💬Community

3
Bugzilla
mongodb: multiple flaws in bundled version of PCRE2015-04-02
Bugzilla
CVE-2014-8964 mingw-pcre: pcre: incorrect handling of zero-repeat assertion conditions [fedora-all]2014-12-25
Bugzilla
CVE-2014-8964 pcre: incorrect handling of zero-repeat assertion conditions2014-11-20
CVE-2014-8964 — Pcre vulnerability | cvebase