CVE-2014-9769
published 2016-03-28CVE-2014-9769: pcre_jit_compile.c in PCRE 8.35 does not properly use table jumps to optimize nested alternatives, which allows remote attackers to cause a denial of service…
PriorityP336high7.3CVSS 3.0
AVNACLPRNUINSUCLILAL
EPSS
2.35%
81.8th percentile
pcre_jit_compile.c in PCRE 8.35 does not properly use table jumps to optimize nested alternatives, which allows remote attackers to cause a denial of service (stack memory corruption) or possibly have unspecified other impact via a crafted string, as demonstrated by packets encountered by Suricata during use of a regular expression in an Emerging Threats Open ruleset.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | pcre3 | < pcre3 2:8.38-1 (bookworm) | pcre3 2:8.38-1 (bookworm) |
| pcre | pcre | — | — |
CVSS provenance
nvdv3.07.3HIGHCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
osv7.3HIGH
vendor_debian7.3HIGH
vendor_redhat7.3HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-v59w-72qc-xg55: pcre_jit_compile
ghsa_unreviewed·2022-05-17
CVE-2014-9769 [HIGH] CWE-119 GHSA-v59w-72qc-xg55: pcre_jit_compile
pcre_jit_compile.c in PCRE 8.35 does not properly use table jumps to optimize nested alternatives, which allows remote attackers to cause a denial of service (stack memory corruption) or possibly have unspecified other impact via a crafted string, as demonstrated by packets encountered by Suricata during use of a regular expression in an Emerging Threats Open ruleset.
OSV
CVE-2014-9769: pcre_jit_compile
osv·2016-03-28·CVSS 7.3
CVE-2014-9769 [HIGH] CVE-2014-9769: pcre_jit_compile
pcre_jit_compile.c in PCRE 8.35 does not properly use table jumps to optimize nested alternatives, which allows remote attackers to cause a denial of service (stack memory corruption) or possibly have unspecified other impact via a crafted string, as demonstrated by packets encountered by Suricata during use of a regular expression in an Emerging Threats Open ruleset.
Ubuntu
PCRE vulnerabilities
vendor_ubuntu·2016-03-29
CVE-2014-9769 PCRE vulnerabilities
Title: PCRE vulnerabilities
Summary: PCRE could be made to crash or run programs if it processed a
specially-crafted regular expression.
It was discovered that PCRE incorrectly handled certain regular
expressions. A remote attacker could use this issue to cause applications
using PCRE to crash, resulting in a denial of service, or possibly execute
arbitrary code.
Instructions: After a standard system update you need to restart applications using PCRE,
such as the Apache HTTP server and Nginx, to make all the necessary
changes.
Red Hat
pcre: incorrect nested table jumps when JIT is used (8.36/6)
vendor_redhat·2016-03-23·CVSS 7.3
CVE-2014-9769 [HIGH] pcre: incorrect nested table jumps when JIT is used (8.36/6)
pcre: incorrect nested table jumps when JIT is used (8.36/6)
pcre_jit_compile.c in PCRE 8.35 does not properly use table jumps to optimize nested alternatives, which allows remote attackers to cause a denial of service (stack memory corruption) or possibly have unspecified other impact via a crafted string, as demonstrated by packets encountered by Suricata during use of a regular expression in an Emerging Threats Open ruleset.
Package: pcre (Red Hat Directory Server 8) - Not affected
Package: pcre (Red Hat Enterprise Linux 5) - Not affected
Package: glib2 (Red Hat Enterprise Linux 6) - Not affected
Package: pcre (Red Hat Enterprise Linux 6) - Not affected
Package: glib2 (Red Hat Enterprise Linux 7) - Not affected
Package: pcre (Red Hat Enterprise Linux 7) - Not affected
Package: v
Debian
CVE-2014-9769: pcre3 - pcre_jit_compile.c in PCRE 8.35 does not properly use table jumps to optimize ne...
vendor_debian·2014·CVSS 7.3
CVE-2014-9769 [HIGH] CVE-2014-9769: pcre3 - pcre_jit_compile.c in PCRE 8.35 does not properly use table jumps to optimize ne...
pcre_jit_compile.c in PCRE 8.35 does not properly use table jumps to optimize nested alternatives, which allows remote attackers to cause a denial of service (stack memory corruption) or possibly have unspecified other impact via a crafted string, as demonstrated by packets encountered by Suricata during use of a regular expression in an Emerging Threats Open ruleset.
Scope: local
bookworm: resolved (fixed in 2:8.38-1)
bullseye: resolved (fixed in 2:8.38-1)
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2014-9769 mingw-glib2: pcre: Segmentation fault on crafted regex when JIT is used [fedora-all]
bugzilla·2016-03-24·CVSS 7.3
CVE-2014-9769 [HIGH] CVE-2014-9769 mingw-glib2: pcre: Segmentation fault on crafted regex when JIT is used [fedora-all]
CVE-2014-9769 mingw-glib2: pcre: Segmentation fault on crafted regex when JIT is used [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple s
Bugzilla
CVE-2014-9769 glib2: pcre: Segmentation fault on crafted regex when JIT is used [fedora-all]
bugzilla·2016-03-24·CVSS 7.3
CVE-2014-9769 [HIGH] CVE-2014-9769 glib2: pcre: Segmentation fault on crafted regex when JIT is used [fedora-all]
CVE-2014-9769 glib2: pcre: Segmentation fault on crafted regex when JIT is used [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple support
Bugzilla
CVE-2014-9769 pcre: incorrect nested table jumps when JIT is used (8.36/6)
bugzilla·2016-03-24·CVSS 7.3
CVE-2014-9769 [HIGH] CVE-2014-9769 pcre: incorrect nested table jumps when JIT is used (8.36/6)
CVE-2014-9769 pcre: incorrect nested table jumps when JIT is used (8.36/6)
It was reported that segmentation fault in surricata appeared when certain regex is processed by pcre_exec in libpcre3.
Bug report:
https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=819050
Discussion:
Created pcre tracking bugs for this issue:
Affects: fedora-all [bug 1320996]
---
Created suricata tracking bugs for this issue:
Affects: fedora-all [bug 1321002]
---
Created glib2 tracking bugs for this issue:
Affects: fedora-all [bug 1320998]
---
Created mingw-glib2 tracking bugs for this issue:
Affects: fedora-all [bug 1320999]
Affects: epel-7 [bug 1321001]
---
Created mingw-pcre tracking bugs for this issue:
Affects: fedora-all [bug 1320997]
Affects: epel-7 [bug 1321000]
---
Could you please prov
Bugzilla
CVE-2014-9769 mingw-pcre: pcre: Segmentation fault on crafted regex when JIT is used [fedora-all]
bugzilla·2016-03-24·CVSS 7.3
CVE-2014-9769 [HIGH] CVE-2014-9769 mingw-pcre: pcre: Segmentation fault on crafted regex when JIT is used [fedora-all]
CVE-2014-9769 mingw-pcre: pcre: Segmentation fault on crafted regex when JIT is used [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple su
Bugzilla
CVE-2014-9769 mingw-pcre: pcre: Segmentation fault on crafted regex when JIT is used [epel-7]
bugzilla·2016-03-24·CVSS 7.3
CVE-2014-9769 [HIGH] CVE-2014-9769 mingw-pcre: pcre: Segmentation fault on crafted regex when JIT is used [epel-7]
CVE-2014-9769 mingw-pcre: pcre: Segmentation fault on crafted regex when JIT is used [epel-7]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora EPEL.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
[bug automatically created by: add-
Bugzilla
CVE-2014-9769 suricata: pcre: Segmentation fault on crafted regex when JIT is used [fedora-all]
bugzilla·2016-03-24·CVSS 7.3
CVE-2014-9769 [HIGH] CVE-2014-9769 suricata: pcre: Segmentation fault on crafted regex when JIT is used [fedora-all]
CVE-2014-9769 suricata: pcre: Segmentation fault on crafted regex when JIT is used [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple supp
Bugzilla
CVE-2014-9769 pcre: Segmentation fault on crafted regex when JIT is used [fedora-all]
bugzilla·2016-03-24·CVSS 7.3
CVE-2014-9769 [HIGH] CVE-2014-9769 pcre: Segmentation fault on crafted regex when JIT is used [fedora-all]
CVE-2014-9769 pcre: Segmentation fault on crafted regex when JIT is used [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple supported vers
Bugzilla
CVE-2014-9769 mingw-glib2: pcre: Segmentation fault on crafted regex when JIT is used [epel-7]
bugzilla·2016-03-24·CVSS 7.3
CVE-2014-9769 [HIGH] CVE-2014-9769 mingw-glib2: pcre: Segmentation fault on crafted regex when JIT is used [epel-7]
CVE-2014-9769 mingw-glib2: pcre: Segmentation fault on crafted regex when JIT is used [epel-7]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora EPEL.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
[bug automatically created by: add
http://vcs.pcre.org/pcre?view=revision&revision=1475http://www.openwall.com/lists/oss-security/2016/03/26/1http://www.securityfocus.com/bid/85570http://www.securitytracker.com/id/1035424https://bugs.debian.org/819050https://redmine.openinfosecfoundation.org/issues/1693http://vcs.pcre.org/pcre?view=revision&revision=1475http://www.openwall.com/lists/oss-security/2016/03/26/1http://www.securityfocus.com/bid/85570http://www.securitytracker.com/id/1035424https://bugs.debian.org/819050https://redmine.openinfosecfoundation.org/issues/1693
2016-03-28
Published