CVE-2015-2325
published 2020-01-14CVE-2015-2325: The compile_branch function in PCRE before 8.37 allows context-dependent attackers to compile incorrect code, cause a denial of service (out-of-bounds heap…
PriorityP434high7.8CVSS 3.1
AVLACLPRNUIRSUCHIHAH
EPSS
1.57%
72.7th percentile
The compile_branch function in PCRE before 8.37 allows context-dependent attackers to compile incorrect code, cause a denial of service (out-of-bounds heap read and crash), or possibly have other unspecified impact via a regular expression with a group containing a forward reference repeated a large number of times within a repeated outer group that has a zero minimum quantifier.
Affected
8 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | pcre3 | < pcre3 2:8.35-7.2 (bookworm) | pcre3 2:8.35-7.2 (bookworm) |
| mariadb | mariadb | < 10.0.18 | 10.0.18 |
| opensuse | opensuse | — | — |
| opensuse | opensuse | — | — |
| pcre | pcre | < 8.37 | 8.37 |
| php | php | >= 5.4.0 < 5.4.41 | 5.4.41 |
| php | php | >= 5.5.0 < 5.5.26 | 5.5.26 |
| php | php | >= 5.6.0 < 5.6.9 | 5.6.9 |
CVSS provenance
nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
nvdv2.06.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
osv7.8HIGH
vendor_debian7.8LOW
vendor_redhat7.8HIGH
vendor_ubuntu5.0MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
PCRE vulnerabilities
vendor_ubuntu·2016-03-29
CVE-2014-9769 PCRE vulnerabilities
Title: PCRE vulnerabilities
Summary: PCRE could be made to crash or run programs if it processed a
specially-crafted regular expression.
It was discovered that PCRE incorrectly handled certain regular
expressions. A remote attacker could use this issue to cause applications
using PCRE to crash, resulting in a denial of service, or possibly execute
arbitrary code.
Instructions: After a standard system update you need to restart applications using PCRE,
such as the Apache HTTP server and Nginx, to make all the necessary
changes.
Ubuntu
PCRE vulnerabilities
vendor_ubuntu·2015-07-29·CVSS 5.0
CVE-2014-8964 [MEDIUM] PCRE vulnerabilities
Title: PCRE vulnerabilities
Summary: PCRE could be made to crash or run programs if it processed a
specially-crafted regular expression.
Michele Spagnuolo discovered that PCRE incorrectly handled certain regular
expressions. A remote attacker could use this issue to cause applications
using PCRE to crash, resulting in a denial of service, or possibly execute
arbitrary code. This issue only affected Ubuntu 14.04 LTS. (CVE-2014-8964)
Kai Lu discovered that PCRE incorrectly handled certain regular
expressions. A remote attacker could use this issue to cause applications
using PCRE to crash, resulting in a denial of service, or possibly execute
arbitrary code. This issue only affected Ubuntu 14.04 LTS and Ubuntu 15.04.
(CVE-2015-2325, CVE-2015-2326)
Wen Guanxing discovered that PCRE incorr
Red Hat
pcre: heap buffer overflow in compile_branch()
vendor_redhat·2015-03-23·CVSS 7.8
CVE-2015-2325 [HIGH] CWE-122 pcre: heap buffer overflow in compile_branch()
pcre: heap buffer overflow in compile_branch()
The compile_branch function in PCRE before 8.37 allows context-dependent attackers to compile incorrect code, cause a denial of service (out-of-bounds heap read and crash), or possibly have other unspecified impact via a regular expression with a group containing a forward reference repeated a large number of times within a repeated outer group that has a zero minimum quantifier.
Statement: This issue did not affect the versions of pcre as shipped with Red Hat Enterprise Linux 5, 6, and 7.
Package: pcre (Red Hat Enterprise Linux 5) - Not affected
Package: pcre (Red Hat Enterprise Linux 6) - Not affected
Package: pcre (Red Hat Enterprise Linux 7) - Not affected
Package: php54-php (Red Hat Software Collections) - Not affected
Package: php
Debian
CVE-2015-2325: pcre3 - The compile_branch function in PCRE before 8.37 allows context-dependent attacke...
vendor_debian·2015·CVSS 7.8
CVE-2015-2325 [HIGH] CVE-2015-2325: pcre3 - The compile_branch function in PCRE before 8.37 allows context-dependent attacke...
The compile_branch function in PCRE before 8.37 allows context-dependent attackers to compile incorrect code, cause a denial of service (out-of-bounds heap read and crash), or possibly have other unspecified impact via a regular expression with a group containing a forward reference repeated a large number of times within a repeated outer group that has a zero minimum quantifier.
Scope: local
bookworm: resolved (fixed in 2:8.35-7.2)
bullseye: resolved (fixed in 2:8.35-7.2)
GHSA
GHSA-mwr9-2r49-jwhg: The compile_branch function in PCRE before 8
ghsa_unreviewed·2022-05-24
CVE-2015-2325 [HIGH] CWE-125 GHSA-mwr9-2r49-jwhg: The compile_branch function in PCRE before 8
The compile_branch function in PCRE before 8.37 allows context-dependent attackers to compile incorrect code, cause a denial of service (out-of-bounds heap read and crash), or possibly have other unspecified impact via a regular expression with a group containing a forward reference repeated a large number of times within a repeated outer group that has a zero minimum quantifier.
OSV
CVE-2015-2325: The compile_branch function in PCRE before 8
osv·2020-01-14·CVSS 7.8
CVE-2015-2325 [HIGH] CVE-2015-2325: The compile_branch function in PCRE before 8
The compile_branch function in PCRE before 8.37 allows context-dependent attackers to compile incorrect code, cause a denial of service (out-of-bounds heap read and crash), or possibly have other unspecified impact via a regular expression with a group containing a forward reference repeated a large number of times within a repeated outer group that has a zero minimum quantifier.
OSV
pcre3 vulnerabilities
osv·2015-07-29·CVSS 5.0
CVE-2014-8964 [MEDIUM] pcre3 vulnerabilities
pcre3 vulnerabilities
Michele Spagnuolo discovered that PCRE incorrectly handled certain regular
expressions. A remote attacker could use this issue to cause applications
using PCRE to crash, resulting in a denial of service, or possibly execute
arbitrary code. This issue only affected Ubuntu 14.04 LTS. (CVE-2014-8964)
Kai Lu discovered that PCRE incorrectly handled certain regular
expressions. A remote attacker could use this issue to cause applications
using PCRE to crash, resulting in a denial of service, or possibly execute
arbitrary code. This issue only affected Ubuntu 14.04 LTS and Ubuntu 15.04.
(CVE-2015-2325, CVE-2015-2326)
Wen Guanxing discovered that PCRE incorrectly handled certain regular
expressions. A remote attacker could use this issue to cause applications
using PCRE t
No detection rules found.
No public exploits indexed.
Tenable
[R4] SecurityCenter 5.0.0.1 Affected by Third-party Library
blogs_tenable·2015-06-15
[R4] SecurityCenter 5.0.0.1 Affected by Third-party Library
## Cloud Exposure
Tenable Cloud Security (CNAPP) Request a demo
Tenable Cloud Vulnerability Management Request a demo
Tenable CIEM Request a demo
Secure your cloud
## Vulnerability Exposure
Tenable Vulnerability Management Try for free
Tenable Security Center Request a demo
Tenable Web App Scanning Try for free
Tenable Patch Management Request a demo
Tenable Enclave Security Request a demo
Tenable Attack Surface Management Request a demo
Tenable Nessus Try for free
## AI Exposure
Tenable AI Exposure Request a demo
## OT/IoT Exposure
Tenable OT Security Request a demo
## Identity Exposure
Tenable Identity Exposure Request a demo
## Business needs
Active Directory
AI Security Posture Management (AI-SPM)
AWS security
Azure security
Cloud Security Posture Man
Bugzilla
CVE-2015-2325 pcre: heap buffer overflow in compile_branch()
bugzilla·2015-03-30·CVSS 7.8
CVE-2015-2325 [HIGH] CVE-2015-2325 pcre: heap buffer overflow in compile_branch()
CVE-2015-2325 pcre: heap buffer overflow in compile_branch()
A flaw was found in the PCRE library:
PCRE library is prone to a heap overflow vulnerability. Due to insufficient bounds checking inside compile_branch(), the heap memory could be overflowed via a crafted regular expression. Since PCRE library is widely used, this vulnerability should affect many applications using it. An attacker may exploit this issue to execute arbitrary code in the context of the user running the affected application.
Upstream issue:
http://bugs.exim.org/show_bug.cgi?id=1591
Upstream patch:
http://vcs.pcre.org/pcre?revision=1528&view=revision
Statement:
This issue did not affect the versions of pcre as shipped with Red Hat Enterprise Linux 5, 6, and 7.
Discussion:
This issue has been addressed in th
arXiv
Towards the Systematic Testing of Regular Expression Engines
arxiv_fulltext·2026-02-27
Towards the Systematic Testing of Regular Expression Engines
[ ] : Systematic Testing of Regular Expression Engines
Towards the Systematic Testing of Regular Expression Engines
Berk Çakar
0009-0006-6613-5591
Electrical and Computer Engineering\ University
West Lafayette
IN
USA
[email protected]
Dongyoon Lee
0000-0002-2240-3316
Computer Science\ Brook University
Stony Brook
NY
USA
[email protected]
James C. Davis
0000-0003-2495-686X
Electrical and Computer Engineering\ University
West Lafayette
IN
USA
[email protected]
Authors' Contact Information: Berk Çakar, [email protected];
Dongyoon Lee, [email protected];
James C. Davis, [email protected].
Çakar, Lee, and Davis
## Abstract
Software engineers use regular expressions (regexes) across a wide range of domains and tasks.
To support regexes, software projects must in
http://lists.opensuse.org/opensuse-updates/2015-05/msg00014.htmlhttps://bugs.exim.org/show_bug.cgi?id=1591https://fortiguard.com/zeroday/FG-VD-15-015https://www.pcre.org/original/changelog.txthttp://lists.opensuse.org/opensuse-updates/2015-05/msg00014.htmlhttps://bugs.exim.org/show_bug.cgi?id=1591https://fortiguard.com/zeroday/FG-VD-15-015https://www.pcre.org/original/changelog.txt
2020-01-14
Published