CVE-2015-2326
published 2020-01-14CVE-2015-2326: The pcre_compile2 function in PCRE before 8.37 allows context-dependent attackers to compile incorrect code and cause a denial of service (out-of-bounds read)…
PriorityP419medium5.5CVSS 3.1
AVLACLPRNUIRSUCNINAH
EPSS
1.59%
73.0th percentile
The pcre_compile2 function in PCRE before 8.37 allows context-dependent attackers to compile incorrect code and cause a denial of service (out-of-bounds read) via regular expression with a group containing both a forward referencing subroutine call and a recursive back reference, as demonstrated by "((?+1)(\1))/".
Affected
8 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | pcre3 | < pcre3 2:8.35-7.2 (bookworm) | pcre3 2:8.35-7.2 (bookworm) |
| mariadb | mariadb | >= 10.0.0 < 10.0.18 | 10.0.18 |
| opensuse | opensuse | — | — |
| opensuse | opensuse | — | — |
| pcre | pcre | < 8.37 | 8.37 |
| php | php | >= 5.4.0 < 5.4.41 | 5.4.41 |
| php | php | >= 5.5.0 < 5.5.26 | 5.5.26 |
| php | php | >= 5.6.0 < 5.6.9 | 5.6.9 |
CVSS provenance
nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:N/I:N/A:P
osv5.5MEDIUM
vendor_debian5.5MEDIUM
vendor_redhat5.5MEDIUM
vendor_ubuntu5.0MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
PCRE vulnerabilities
vendor_ubuntu·2016-03-29
CVE-2014-9769 PCRE vulnerabilities
Title: PCRE vulnerabilities
Summary: PCRE could be made to crash or run programs if it processed a
specially-crafted regular expression.
It was discovered that PCRE incorrectly handled certain regular
expressions. A remote attacker could use this issue to cause applications
using PCRE to crash, resulting in a denial of service, or possibly execute
arbitrary code.
Instructions: After a standard system update you need to restart applications using PCRE,
such as the Apache HTTP server and Nginx, to make all the necessary
changes.
Ubuntu
PCRE vulnerabilities
vendor_ubuntu·2015-07-29·CVSS 5.0
CVE-2014-8964 [MEDIUM] PCRE vulnerabilities
Title: PCRE vulnerabilities
Summary: PCRE could be made to crash or run programs if it processed a
specially-crafted regular expression.
Michele Spagnuolo discovered that PCRE incorrectly handled certain regular
expressions. A remote attacker could use this issue to cause applications
using PCRE to crash, resulting in a denial of service, or possibly execute
arbitrary code. This issue only affected Ubuntu 14.04 LTS. (CVE-2014-8964)
Kai Lu discovered that PCRE incorrectly handled certain regular
expressions. A remote attacker could use this issue to cause applications
using PCRE to crash, resulting in a denial of service, or possibly execute
arbitrary code. This issue only affected Ubuntu 14.04 LTS and Ubuntu 15.04.
(CVE-2015-2325, CVE-2015-2326)
Wen Guanxing discovered that PCRE incorr
Red Hat
pcre: heap buffer over-read in pcre_compile2() (8.37/23)
vendor_redhat·2015-03-23·CVSS 5.5
CVE-2015-2326 [MEDIUM] CWE-125 pcre: heap buffer over-read in pcre_compile2() (8.37/23)
pcre: heap buffer over-read in pcre_compile2() (8.37/23)
The pcre_compile2 function in PCRE before 8.37 allows context-dependent attackers to compile incorrect code and cause a denial of service (out-of-bounds read) via regular expression with a group containing both a forward referencing subroutine call and a recursive back reference, as demonstrated by "((?+1)(\1))/".
Statement: This issue did not affect the versions of pcre as shipped with Red Hat Enterprise Linux 5, 6, and 7.
Package: pcre (Red Hat Enterprise Linux 5) - Not affected
Package: glib2 (Red Hat Enterprise Linux 6) - Not affected
Package: pcre (Red Hat Enterprise Linux 6) - Not affected
Package: glib2 (Red Hat Enterprise Linux 7) - Not affected
Package: pcre (Red Hat Enterprise Linux 7) - Not affected
Package: php54-
Debian
CVE-2015-2326: pcre3 - The pcre_compile2 function in PCRE before 8.37 allows context-dependent attacker...
vendor_debian·2015·CVSS 5.5
CVE-2015-2326 [MEDIUM] CVE-2015-2326: pcre3 - The pcre_compile2 function in PCRE before 8.37 allows context-dependent attacker...
The pcre_compile2 function in PCRE before 8.37 allows context-dependent attackers to compile incorrect code and cause a denial of service (out-of-bounds read) via regular expression with a group containing both a forward referencing subroutine call and a recursive back reference, as demonstrated by "((?+1)(\1))/".
Scope: local
bookworm: resolved (fixed in 2:8.35-7.2)
bullseye: resolved (fixed in 2:8.35-7.2)
GHSA
GHSA-m793-2mj8-wj8q: The pcre_compile2 function in PCRE before 8
ghsa_unreviewed·2022-05-24
CVE-2015-2326 [MEDIUM] CWE-125 GHSA-m793-2mj8-wj8q: The pcre_compile2 function in PCRE before 8
The pcre_compile2 function in PCRE before 8.37 allows context-dependent attackers to compile incorrect code and cause a denial of service (out-of-bounds read) via regular expression with a group containing both a forward referencing subroutine call and a recursive back reference, as demonstrated by "((?+1)(\1))/".
OSV
CVE-2015-2326: The pcre_compile2 function in PCRE before 8
osv·2020-01-14·CVSS 5.5
CVE-2015-2326 [MEDIUM] CVE-2015-2326: The pcre_compile2 function in PCRE before 8
The pcre_compile2 function in PCRE before 8.37 allows context-dependent attackers to compile incorrect code and cause a denial of service (out-of-bounds read) via regular expression with a group containing both a forward referencing subroutine call and a recursive back reference, as demonstrated by "((?+1)(\1))/".
OSV
pcre3 vulnerabilities
osv·2015-07-29·CVSS 5.0
CVE-2014-8964 [MEDIUM] pcre3 vulnerabilities
pcre3 vulnerabilities
Michele Spagnuolo discovered that PCRE incorrectly handled certain regular
expressions. A remote attacker could use this issue to cause applications
using PCRE to crash, resulting in a denial of service, or possibly execute
arbitrary code. This issue only affected Ubuntu 14.04 LTS. (CVE-2014-8964)
Kai Lu discovered that PCRE incorrectly handled certain regular
expressions. A remote attacker could use this issue to cause applications
using PCRE to crash, resulting in a denial of service, or possibly execute
arbitrary code. This issue only affected Ubuntu 14.04 LTS and Ubuntu 15.04.
(CVE-2015-2325, CVE-2015-2326)
Wen Guanxing discovered that PCRE incorrectly handled certain regular
expressions. A remote attacker could use this issue to cause applications
using PCRE t
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2015-2326 pcre: heap buffer over-read in pcre_compile2() (8.37/23)
bugzilla·2015-03-30·CVSS 5.5
CVE-2015-2326 [MEDIUM] CVE-2015-2326 pcre: heap buffer over-read in pcre_compile2() (8.37/23)
CVE-2015-2326 pcre: heap buffer over-read in pcre_compile2() (8.37/23)
A flaw was found in the PCRE library:
PCRE library is prone to a vulnerability which leads to Heap overflow. Without enough bound checking inside pcre_compile2(), the heap memory could be overflowed via a crafted regular expression. Since PCRE library is widely used, this vulnerability should affect many applications. An attacker may exploit this issue to execute arbitrary code in the context of the user running the affected application.
Upstream issue:
http://bugs.exim.org/show_bug.cgi?id=1592
Upstream patch:
http://vcs.pcre.org/pcre?revision=1529&view=revision
Statement:
This issue did not affect the versions of pcre as shipped with Red Hat Enterprise Linux 5, 6, and 7.
Discussion:
8.34 seems to be the first
Tenable
[R4] SecurityCenter 5.0.0.1 Affected by Third-party Library
blogs_tenable·2015-06-15
[R4] SecurityCenter 5.0.0.1 Affected by Third-party Library
## Cloud Exposure
Tenable Cloud Security (CNAPP) Request a demo
Tenable Cloud Vulnerability Management Request a demo
Tenable CIEM Request a demo
Secure your cloud
## Vulnerability Exposure
Tenable Vulnerability Management Try for free
Tenable Security Center Request a demo
Tenable Web App Scanning Try for free
Tenable Patch Management Request a demo
Tenable Enclave Security Request a demo
Tenable Attack Surface Management Request a demo
Tenable Nessus Try for free
## AI Exposure
Tenable AI Exposure Request a demo
## OT/IoT Exposure
Tenable OT Security Request a demo
## Identity Exposure
Tenable Identity Exposure Request a demo
## Business needs
Active Directory
AI Security Posture Management (AI-SPM)
AWS security
Azure security
Cloud Security Posture Man
http://lists.opensuse.org/opensuse-updates/2015-05/msg00014.htmlhttps://bugs.exim.org/show_bug.cgi?id=1592https://fortiguard.com/zeroday/FG-VD-15-016https://www.pcre.org/original/changelog.txthttp://lists.opensuse.org/opensuse-updates/2015-05/msg00014.htmlhttps://bugs.exim.org/show_bug.cgi?id=1592https://fortiguard.com/zeroday/FG-VD-15-016https://www.pcre.org/original/changelog.txt
2020-01-14
Published