CVE-2017-7186
published 2017-03-20CVE-2017-7186: libpcre1 in PCRE 8.40 and libpcre2 in PCRE2 10.23 allow remote attackers to cause a denial of service (segmentation violation for read access, and application…
PriorityP335high7.5CVSS 3.0
AVNACLPRNUINSUCNINAH
EPSS
5.03%
91.3th percentile
libpcre1 in PCRE 8.40 and libpcre2 in PCRE2 10.23 allow remote attackers to cause a denial of service (segmentation violation for read access, and application crash) by triggering an invalid Unicode property lookup.
Affected
8 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | pcre2 | < pcre2 10.22-3 (bookworm) | pcre2 10.22-3 (bookworm) |
| debian | pcre3 | < pcre2 10.22-3 (bookworm) | pcre2 10.22-3 (bookworm) |
| pcre | pcre | — | — |
| pcre | pcre2 | — | — |
| pcre | pcre2 | >= 0 < 10.22-3 | 10.22-3 |
| pcre | pcre2 | >= 0 < 10.22-3 | 10.22-3 |
| pcre | pcre2 | >= 0 < 10.22-3 | 10.22-3 |
| pcre | pcre2 | >= 0 < 10.22-3 | 10.22-3 |
CVSS provenance
nvdv3.07.5HIGHCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:N/A:P
osv7.5HIGH
vendor_debian7.5HIGH
vendor_redhat7.5HIGH
vendor_ubuntu7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
PCRE vulnerabilities
vendor_ubuntu·2022-10-10·CVSS 7.5
CVE-2017-7186 [HIGH] PCRE vulnerabilities
Title: PCRE vulnerabilities
Summary: PCRE could be made to crash if it received specially crafted
input.
It was discovered that PCRE incorrectly handled certain regular expressions.
A remote attacker could use this issue to cause applications using PCRE to
crash, resulting in a denial of service. (CVE-2017-6004)
It was discovered that PCRE incorrectly handled certain Unicode encoding. A
remote attacker could use this issue to cause applications using PCRE to
crash, resulting in a denial of service. (CVE-2017-7186)
Instructions: In general, a standard system update will make all the necessary changes.
Red Hat
pcre: Invalid Unicode property lookup (8.41/7, 10.24/2)
vendor_redhat·2017-02-23·CVSS 7.5
CVE-2017-7186 [HIGH] CWE-20 pcre: Invalid Unicode property lookup (8.41/7, 10.24/2)
pcre: Invalid Unicode property lookup (8.41/7, 10.24/2)
libpcre1 in PCRE 8.40 and libpcre2 in PCRE2 10.23 allow remote attackers to cause a denial of service (segmentation violation for read access, and application crash) by triggering an invalid Unicode property lookup.
Statement: Red Hat Product Security has rated this issue as having Moderate security impact. This issue is not currently planned to be addressed in future updates. For additional information, refer to the Issue Severity Classification: https://access.redhat.com/security/updates/classification/.
Package: pcre (Red Hat Directory Server 8) - Not affected
Package: pcre (Red Hat Enterprise Linux 5) - Not affected
Package: glib2 (Red Hat Enterprise Linux 6) - Not affected
Package: pcre (Red Hat Enterprise Linux 6) - Not af
Debian
CVE-2017-7186: pcre2 - libpcre1 in PCRE 8.40 and libpcre2 in PCRE2 10.23 allow remote attackers to caus...
vendor_debian·2017·CVSS 7.5
CVE-2017-7186 [HIGH] CVE-2017-7186: pcre2 - libpcre1 in PCRE 8.40 and libpcre2 in PCRE2 10.23 allow remote attackers to caus...
libpcre1 in PCRE 8.40 and libpcre2 in PCRE2 10.23 allow remote attackers to cause a denial of service (segmentation violation for read access, and application crash) by triggering an invalid Unicode property lookup.
Scope: local
bookworm: resolved (fixed in 10.22-3)
bullseye: resolved (fixed in 10.22-3)
forky: resolved (fixed in 10.22-3)
sid: resolved (fixed in 10.22-3)
trixie: resolved (fixed in 10.22-3)
OSV
pcre3 vulnerabilities
osv·2022-10-10·CVSS 7.5
CVE-2017-6004 [HIGH] pcre3 vulnerabilities
pcre3 vulnerabilities
It was discovered that PCRE incorrectly handled certain regular expressions.
A remote attacker could use this issue to cause applications using PCRE to
crash, resulting in a denial of service. (CVE-2017-6004)
It was discovered that PCRE incorrectly handled certain Unicode encoding. A
remote attacker could use this issue to cause applications using PCRE to
crash, resulting in a denial of service. (CVE-2017-7186)
GHSA
GHSA-vrw4-ffp3-c5mv: libpcre1 in PCRE 8
ghsa_unreviewed·2022-05-14
CVE-2017-7186 [HIGH] CWE-119 GHSA-vrw4-ffp3-c5mv: libpcre1 in PCRE 8
libpcre1 in PCRE 8.40 and libpcre2 in PCRE2 10.23 allow remote attackers to cause a denial of service (segmentation violation for read access, and application crash) by triggering an invalid Unicode property lookup.
OSV
leptonlib vulnerabilities
osv·2021-03-15·CVSS 3.3
CVE-2017-18196 leptonlib vulnerabilities
leptonlib vulnerabilities
It was discovered that Leptonica incorrectly handled path names. An
attacker could possibly use this issue to obtain sensitive information.
This issue only affected Ubuntu 16.04 ESM. (CVE-2017-18196)
It was discovered that Leptonica incorrectly handled certain input
arguments. An attacker could possibly use this issue to execute arbitrary
commands. (CVE-2018-3836)
It was discovered that Leptonica incorrectly handled input arguments. An
attacker could possibly use this issue to cause a denial of service or
other unspecified impact. (CVE-2018-7186)
OSV
CVE-2017-7186: libpcre1 in PCRE 8
osv·2017-03-20·CVSS 7.5
CVE-2017-7186 [HIGH] CVE-2017-7186: libpcre1 in PCRE 8
libpcre1 in PCRE 8.40 and libpcre2 in PCRE2 10.23 allow remote attackers to cause a denial of service (segmentation violation for read access, and application crash) by triggering an invalid Unicode property lookup.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2017-7186 mingw-glib2: pcre, pcre2: Invalid Unicode property lookup [fedora-all]
bugzilla·2017-03-21·CVSS 7.5
CVE-2017-7186 [HIGH] CVE-2017-7186 mingw-glib2: pcre, pcre2: Invalid Unicode property lookup [fedora-all]
CVE-2017-7186 mingw-glib2: pcre, pcre2: Invalid Unicode property lookup [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple supported v
Bugzilla
CVE-2017-7186 mingw-pcre: pcre, pcre2: Invalid Unicode property lookup [epel-7]
bugzilla·2017-03-21·CVSS 7.5
CVE-2017-7186 [HIGH] CVE-2017-7186 mingw-pcre: pcre, pcre2: Invalid Unicode property lookup [epel-7]
CVE-2017-7186 mingw-pcre: pcre, pcre2: Invalid Unicode property lookup [epel-7]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of epel-7.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
Discussion:
Use the following template to for the 'fe
Bugzilla
CVE-2017-7186 glib2: pcre, pcre2: Invalid Unicode property lookup [fedora-all]
bugzilla·2017-03-21·CVSS 7.5
CVE-2017-7186 [HIGH] CVE-2017-7186 glib2: pcre, pcre2: Invalid Unicode property lookup [fedora-all]
CVE-2017-7186 glib2: pcre, pcre2: Invalid Unicode property lookup [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple supported version
Bugzilla
CVE-2017-7186 mingw-glib2: pcre, pcre2: Invalid Unicode property lookup [epel-7]
bugzilla·2017-03-21·CVSS 7.5
CVE-2017-7186 [HIGH] CVE-2017-7186 mingw-glib2: pcre, pcre2: Invalid Unicode property lookup [epel-7]
CVE-2017-7186 mingw-glib2: pcre, pcre2: Invalid Unicode property lookup [epel-7]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of epel-7.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
Discussion:
Use the following template to for the 'f
Bugzilla
CVE-2017-7186 pcre2: pcre, pcre2: Invalid Unicode property lookup [epel-7]
bugzilla·2017-03-21·CVSS 7.5
CVE-2017-7186 [HIGH] CVE-2017-7186 pcre2: pcre, pcre2: Invalid Unicode property lookup [epel-7]
CVE-2017-7186 pcre2: pcre, pcre2: Invalid Unicode property lookup [epel-7]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of epel-7.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
Discussion:
Use the following template to for the 'fedpkg
Bugzilla
CVE-2017-7186 pcre2: pcre, pcre2: Invalid Unicode property lookup [epel-6]
bugzilla·2017-03-21·CVSS 7.5
CVE-2017-7186 [HIGH] CVE-2017-7186 pcre2: pcre, pcre2: Invalid Unicode property lookup [epel-6]
CVE-2017-7186 pcre2: pcre, pcre2: Invalid Unicode property lookup [epel-6]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of epel-6.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
Discussion:
Use the following template to for the 'fedpkg
Bugzilla
CVE-2017-7186 mingw-pcre: pcre, pcre2: Invalid Unicode property lookup [fedora-all]
bugzilla·2017-03-21·CVSS 7.5
CVE-2017-7186 [HIGH] CVE-2017-7186 mingw-pcre: pcre, pcre2: Invalid Unicode property lookup [fedora-all]
CVE-2017-7186 mingw-pcre: pcre, pcre2: Invalid Unicode property lookup [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple supported ve
Bugzilla
CVE-2017-7186 pcre: Invalid Unicode property lookup (8.41/7, 10.24/2)
bugzilla·2017-03-21·CVSS 7.5
CVE-2017-7186 [HIGH] CVE-2017-7186 pcre: Invalid Unicode property lookup (8.41/7, 10.24/2)
CVE-2017-7186 pcre: Invalid Unicode property lookup (8.41/7, 10.24/2)
A vulnerability was found in pcre caused by trying to find a Unicode property for a code value greater than 0x10ffff, the Unicode maximum, when running in non-UTF mode (where character values can be up to 0xffffffff).
Upstream bug:
https://bugs.exim.org/show_bug.cgi?id=2052
References:
https://blogs.gentoo.org/ago/2017/03/14/libpcre-invalid-memory-read-in-match-pcre_exec-c/
Upstream patches (pcre):
https://vcs.pcre.org/pcre?view=revision&revision=1688
Upstream patches (pcre2):
https://vcs.pcre.org/pcre2?view=revision&revision=670
Discussion:
Created glib2 tracking bugs for this issue:
Affects: fedora-all [bug 1434517]
Created mingw-glib2 tracking bugs for this issue:
Affects: epel-7 [bug 1434515]
Affects:
http://www.securityfocus.com/bid/97030https://access.redhat.com/errata/RHSA-2018:2486https://blogs.gentoo.org/ago/2017/03/14/libpcre-invalid-memory-read-in-match-pcre_exec-c/https://bugs.exim.org/show_bug.cgi?id=2052https://security.gentoo.org/glsa/201710-09https://security.gentoo.org/glsa/201710-25https://vcs.pcre.org/pcre/code/trunk/pcre_internal.h?r1=1649&r2=1688&sortby=datehttps://vcs.pcre.org/pcre/code/trunk/pcre_ucd.c?r1=1490&r2=1688&sortby=datehttps://vcs.pcre.org/pcre2/code/trunk/src/pcre2_internal.h?r1=600&r2=670&sortby=datehttps://vcs.pcre.org/pcre2/code/trunk/src/pcre2_ucd.c?r1=316&r2=670&sortby=datehttp://www.securityfocus.com/bid/97030https://access.redhat.com/errata/RHSA-2018:2486https://blogs.gentoo.org/ago/2017/03/14/libpcre-invalid-memory-read-in-match-pcre_exec-c/https://bugs.exim.org/show_bug.cgi?id=2052https://security.gentoo.org/glsa/201710-09https://security.gentoo.org/glsa/201710-25https://vcs.pcre.org/pcre/code/trunk/pcre_internal.h?r1=1649&r2=1688&sortby=datehttps://vcs.pcre.org/pcre/code/trunk/pcre_ucd.c?r1=1490&r2=1688&sortby=datehttps://vcs.pcre.org/pcre2/code/trunk/src/pcre2_internal.h?r1=600&r2=670&sortby=datehttps://vcs.pcre.org/pcre2/code/trunk/src/pcre2_ucd.c?r1=316&r2=670&sortby=date
2017-03-20
Published