CVE-2014-9769 — Improper Restriction of Operations within the Bounds of a Memory Buffer in Pcre
CWE-119 — Improper Restriction of Operations within the Bounds of a Memory Buffer14 documents7 sources
Severity
7.3HIGHNVD
EPSS
0.9%
top 23.82%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedMar 28
Latest updateMay 17
Description
pcre_jit_compile.c in PCRE 8.35 does not properly use table jumps to optimize nested alternatives, which allows remote attackers to cause a denial of service (stack memory corruption) or possibly have unspecified other impact via a crafted string, as demonstrated by packets encountered by Suricata during use of a regular expression in an Emerging Threats Open ruleset.
CVSS vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:LExploitability: 3.9 | Impact: 3.4
Affected Packages2 packages
🔴Vulnerability Details
2📋Vendor Advisories
3💬Community
8Bugzilla▶
CVE-2014-9769 mingw-glib2: pcre: Segmentation fault on crafted regex when JIT is used [fedora-all]↗2016-03-24
Bugzilla▶
CVE-2014-9769 glib2: pcre: Segmentation fault on crafted regex when JIT is used [fedora-all]↗2016-03-24
Bugzilla▶
CVE-2014-9769 mingw-pcre: pcre: Segmentation fault on crafted regex when JIT is used [fedora-all]↗2016-03-24
Bugzilla▶
CVE-2014-9769 mingw-pcre: pcre: Segmentation fault on crafted regex when JIT is used [epel-7]↗2016-03-24