CVE-2015-2328
published 2015-12-02CVE-2015-2328: PCRE before 8.36 mishandles the /((?(R)a|(?1)))+/ pattern and related patterns with certain recursion, which allows remote attackers to cause a denial of…
PriorityP335high7.5CVSS 2.0
AVNACLAuNCPIPAP
EPSS
5.24%
91.6th percentile
PCRE before 8.36 mishandles the /((?(R)a|(?1)))+/ pattern and related patterns with certain recursion, which allows remote attackers to cause a denial of service (segmentation fault) or possibly have unspecified other impact via a crafted regular expression, as demonstrated by a JavaScript RegExp object encountered by Konqueror.
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | pcre3 | < pcre3 2:8.35-7.2 (bookworm) | pcre3 2:8.35-7.2 (bookworm) |
| oracle | linux | — | — |
| pcre | pcre | <= 8.35 | — |
CVSS provenance
nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
osv7.5HIGH
vendor_debian7.5LOW
vendor_redhat7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
PCRE vulnerabilities
vendor_ubuntu·2016-03-29
CVE-2014-9769 PCRE vulnerabilities
Title: PCRE vulnerabilities
Summary: PCRE could be made to crash or run programs if it processed a
specially-crafted regular expression.
It was discovered that PCRE incorrectly handled certain regular
expressions. A remote attacker could use this issue to cause applications
using PCRE to crash, resulting in a denial of service, or possibly execute
arbitrary code.
Instructions: After a standard system update you need to restart applications using PCRE,
such as the Apache HTTP server and Nginx, to make all the necessary
changes.
Debian
CVE-2015-2328: pcre3 - PCRE before 8.36 mishandles the /((?(R)a|(?1)))+/ pattern and related patterns w...
vendor_debian·2015·CVSS 7.5
CVE-2015-2328 [HIGH] CVE-2015-2328: pcre3 - PCRE before 8.36 mishandles the /((?(R)a|(?1)))+/ pattern and related patterns w...
PCRE before 8.36 mishandles the /((?(R)a|(?1)))+/ pattern and related patterns with certain recursion, which allows remote attackers to cause a denial of service (segmentation fault) or possibly have unspecified other impact via a crafted regular expression, as demonstrated by a JavaScript RegExp object encountered by Konqueror.
Scope: local
bookworm: resolved (fixed in 2:8.35-7.2)
bullseye: resolved (fixed in 2:8.35-7.2)
Red Hat
pcre: infinite recursion compiling pattern with recursive reference in a group with indefinite repeat (8.36/20)
vendor_redhat·2014-08-07·CVSS 7.5
CVE-2015-2328 [HIGH] CWE-674 pcre: infinite recursion compiling pattern with recursive reference in a group with indefinite repeat (8.36/20)
pcre: infinite recursion compiling pattern with recursive reference in a group with indefinite repeat (8.36/20)
PCRE before 8.36 mishandles the /((?(R)a|(?1)))+/ pattern and related patterns with certain recursion, which allows remote attackers to cause a denial of service (segmentation fault) or possibly have unspecified other impact via a crafted regular expression, as demonstrated by a JavaScript RegExp object encountered by Konqueror.
Package: pcre (Red Hat Directory Server 8) - Not affected
Package: pcre (Red Hat Enterprise Linux 5) - Not affected
Package: glib2 (Red Hat Enterprise Linux 6) - Not affected
Package: pcre (Red Hat Enterprise Linux 6) - Not affected
Package: glib2 (Red Hat Enterprise Linux 7) - Will not fix
Package: virtuoso-opensource (Red Hat Enterprise Linux 7)
GHSA
GHSA-4h7h-5fv8-m6hg: PCRE before 8
ghsa_unreviewed·2022-05-13
CVE-2015-2328 [HIGH] GHSA-4h7h-5fv8-m6hg: PCRE before 8
PCRE before 8.36 mishandles the /((?(R)a|(?1)))+/ pattern and related patterns with certain recursion, which allows remote attackers to cause a denial of service (segmentation fault) or possibly have unspecified other impact via a crafted regular expression, as demonstrated by a JavaScript RegExp object encountered by Konqueror.
OSV
CVE-2015-2328: PCRE before 8
osv·2015-12-02·CVSS 7.5
CVE-2015-2328 [HIGH] CVE-2015-2328: PCRE before 8
PCRE before 8.36 mishandles the /((?(R)a|(?1)))+/ pattern and related patterns with certain recursion, which allows remote attackers to cause a denial of service (segmentation fault) or possibly have unspecified other impact via a crafted regular expression, as demonstrated by a JavaScript RegExp object encountered by Konqueror.
No detection rules found.
No public exploits indexed.
arXiv
Towards the Systematic Testing of Regular Expression Engines
arxiv_fulltext·2026-02-27
Towards the Systematic Testing of Regular Expression Engines
[ ] : Systematic Testing of Regular Expression Engines
Towards the Systematic Testing of Regular Expression Engines
Berk Çakar
0009-0006-6613-5591
Electrical and Computer Engineering\ University
West Lafayette
IN
USA
[email protected]
Dongyoon Lee
0000-0002-2240-3316
Computer Science\ Brook University
Stony Brook
NY
USA
[email protected]
James C. Davis
0000-0003-2495-686X
Electrical and Computer Engineering\ University
West Lafayette
IN
USA
[email protected]
Authors' Contact Information: Berk Çakar, [email protected];
Dongyoon Lee, [email protected];
James C. Davis, [email protected].
Çakar, Lee, and Davis
## Abstract
Software engineers use regular expressions (regexes) across a wide range of domains and tasks.
To support regexes, software projects must in
Bugzilla
CVE-2015-2328 pcre: infinite recursion compiling pattern with recursive reference in a group with indefinite repeat (8.36/20)
bugzilla·2015-11-25·CVSS 7.5
CVE-2015-2328 [HIGH] CVE-2015-2328 pcre: infinite recursion compiling pattern with recursive reference in a group with indefinite repeat (8.36/20)
CVE-2015-2328 pcre: infinite recursion compiling pattern with recursive reference in a group with indefinite repeat (8.36/20)
A stack-based buffer overflow vulnerability was found in compile_regex(), triggered via crafted regular expression.
Upstream bug (contains reproducer):
https://bugs.exim.org/show_bug.cgi?id=1515
Upstream patch:
http://vcs.pcre.org/pcre?view=revision&revision=1498
CVE request:
http://www.openwall.com/lists/oss-security/2015/05/31/4
Discussion:
Created pcre tracking bugs for this issue:
Affects: fedora-all [bug 1285401]
---
Upstream fixed it in 8.36. Simple reproducer is crash when compiling /((?(R)a|(?1)))*/ expression.
---
This has already been fixed as bug #1128577 in Fedora. No supported Fedora is affected since 2014-08-11.
---
This is not a stack
Bugzilla
CVE-2015-3155 foreman: the _session_id cookie is issued without the Secure flag
bugzilla·2015-04-28·CVSS 5.0
CVE-2015-3155 [MEDIUM] CVE-2015-3155 foreman: the _session_id cookie is issued without the Secure flag
CVE-2015-3155 foreman: the _session_id cookie is issued without the Secure flag
It was reported that the _session_id cookie in Foreman is set without the Secure flag.
This may allow an attacker to perform a "session hijacking" attack.
Upstream bug: http://projects.theforeman.org/issues/10275
Proposed fix: https://github.com/theforeman/foreman/pull/2328
Discussion:
Acknowledgements:
Red Hat would like to thank Rufus Järnefelt of Coresec for reporting this issue.
---
This issue has been addressed in the following products:
Red Hat Satellite 6.1
Via RHSA-2015:1591 https://access.redhat.com/errata/RHSA-2015:1591
---
This issue has been addressed in the following products:
Red Hat Satellite 6.1
Via RHSA-2015:1592 https://access.redhat.com/errata/RHSA-2015:1592
http://rhn.redhat.com/errata/RHSA-2016-1025.htmlhttp://rhn.redhat.com/errata/RHSA-2016-2750.htmlhttp://vcs.pcre.org/pcre/code/trunk/ChangeLog?view=markuphttp://www-01.ibm.com/support/docview.wss?uid=isg3T1023886http://www.fortiguard.com/advisory/FG-VD-15-014/http://www.openwall.com/lists/oss-security/2015/11/29/1http://www.oracle.com/technetwork/topics/security/linuxbulletinapr2016-2952096.htmlhttp://www.securityfocus.com/bid/74924https://bugs.exim.org/show_bug.cgi?id=1515https://jira.mongodb.org/browse/SERVER-17252http://rhn.redhat.com/errata/RHSA-2016-1025.htmlhttp://rhn.redhat.com/errata/RHSA-2016-2750.htmlhttp://vcs.pcre.org/pcre/code/trunk/ChangeLog?view=markuphttp://www-01.ibm.com/support/docview.wss?uid=isg3T1023886http://www.fortiguard.com/advisory/FG-VD-15-014/http://www.openwall.com/lists/oss-security/2015/11/29/1http://www.oracle.com/technetwork/topics/security/linuxbulletinapr2016-2952096.htmlhttp://www.securityfocus.com/bid/74924https://bugs.exim.org/show_bug.cgi?id=1515https://jira.mongodb.org/browse/SERVER-17252
2015-12-02
Published