CVE-2014-9769Improper Restriction of Operations within the Bounds of a Memory Buffer in Pcre

Severity
7.3HIGHNVD
EPSS
0.9%
top 23.82%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedMar 28
Latest updateMay 17

Description

pcre_jit_compile.c in PCRE 8.35 does not properly use table jumps to optimize nested alternatives, which allows remote attackers to cause a denial of service (stack memory corruption) or possibly have unspecified other impact via a crafted string, as demonstrated by packets encountered by Suricata during use of a regular expression in an Emerging Threats Open ruleset.

CVSS vector

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:LExploitability: 3.9 | Impact: 3.4

Affected Packages2 packages

debiandebian/pcre3< pcre3 2:8.38-1 (bookworm)
NVDpcre/pcre8.35

🔴Vulnerability Details

2
GHSA
GHSA-v59w-72qc-xg55: pcre_jit_compile2022-05-17
OSV
CVE-2014-9769: pcre_jit_compile2016-03-28

📋Vendor Advisories

3
Ubuntu
PCRE vulnerabilities2016-03-29
Red Hat
pcre: incorrect nested table jumps when JIT is used (8.36/6)2016-03-23
Debian
CVE-2014-9769: pcre3 - pcre_jit_compile.c in PCRE 8.35 does not properly use table jumps to optimize ne...2014

💬Community

8
Bugzilla
CVE-2014-9769 mingw-glib2: pcre: Segmentation fault on crafted regex when JIT is used [fedora-all]2016-03-24
Bugzilla
CVE-2014-9769 glib2: pcre: Segmentation fault on crafted regex when JIT is used [fedora-all]2016-03-24
Bugzilla
CVE-2014-9769 pcre: incorrect nested table jumps when JIT is used (8.36/6)2016-03-24
Bugzilla
CVE-2014-9769 mingw-pcre: pcre: Segmentation fault on crafted regex when JIT is used [fedora-all]2016-03-24
Bugzilla
CVE-2014-9769 mingw-pcre: pcre: Segmentation fault on crafted regex when JIT is used [epel-7]2016-03-24
CVE-2014-9769 — Pcre vulnerability | cvebase