CVE-2017-7244
published 2017-03-23CVE-2017-7244: The _pcre32_xclass function in pcre_xclass.c in libpcre1 in PCRE 8.40 allows remote attackers to cause a denial of service (invalid memory read) via a crafted…
PriorityP419medium5.5CVSS 3.0
AVLACLPRNUIRSUCNINAH
EPSS
1.99%
78.5th percentile
The _pcre32_xclass function in pcre_xclass.c in libpcre1 in PCRE 8.40 allows remote attackers to cause a denial of service (invalid memory read) via a crafted file.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | pcre3 | < pcre3 2:8.39-3 (bookworm) | pcre3 2:8.39-3 (bookworm) |
| pcre | pcre | — | — |
CVSS provenance
nvdv3.05.5MEDIUMCVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:N/I:N/A:P
osv5.5MEDIUM
vendor_debian5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-2j3f-972q-6fv5: The _pcre32_xclass function in pcre_xclass
ghsa_unreviewed·2022-05-14
CVE-2017-7244 [MEDIUM] CWE-125 GHSA-2j3f-972q-6fv5: The _pcre32_xclass function in pcre_xclass
The _pcre32_xclass function in pcre_xclass.c in libpcre1 in PCRE 8.40 allows remote attackers to cause a denial of service (invalid memory read) via a crafted file.
OSV
CVE-2017-7244: The _pcre32_xclass function in pcre_xclass
osv·2017-03-23·CVSS 5.5
CVE-2017-7244 [MEDIUM] CVE-2017-7244: The _pcre32_xclass function in pcre_xclass
The _pcre32_xclass function in pcre_xclass.c in libpcre1 in PCRE 8.40 allows remote attackers to cause a denial of service (invalid memory read) via a crafted file.
Red Hat
pcre: invalid memory read in _pcre32_xclass (pcre_xclass.c)
vendor_redhat·2017-03-23·CVSS 5.5
CVE-2017-7244 [MEDIUM] CWE-20 pcre: invalid memory read in _pcre32_xclass (pcre_xclass.c)
pcre: invalid memory read in _pcre32_xclass (pcre_xclass.c)
The _pcre32_xclass function in pcre_xclass.c in libpcre1 in PCRE 8.40 allows remote attackers to cause a denial of service (invalid memory read) via a crafted file.
Package: pcre (Red Hat Enterprise Linux 5) - Will not fix
Package: glib2 (Red Hat Enterprise Linux 6) - Will not fix
Package: pcre (Red Hat Enterprise Linux 6) - Will not fix
Package: glib2 (Red Hat Enterprise Linux 7) - Will not fix
Package: pcre (Red Hat Enterprise Linux 7) - Will not fix
Package: pcre2 (Red Hat Enterprise Linux 7) - Not affected
Package: virtuoso-opensource (Red Hat Enterprise Linux 7) - Will not fix
Package: httpd (Red Hat JBoss Enterprise Web Server 1) - Will not fix
Package: httpd (Red Hat JBoss Enterprise Web Server 2) - Will not fix
Debian
CVE-2017-7244: pcre3 - The _pcre32_xclass function in pcre_xclass.c in libpcre1 in PCRE 8.40 allows rem...
vendor_debian·2017·CVSS 5.5
CVE-2017-7244 [MEDIUM] CVE-2017-7244: pcre3 - The _pcre32_xclass function in pcre_xclass.c in libpcre1 in PCRE 8.40 allows rem...
The _pcre32_xclass function in pcre_xclass.c in libpcre1 in PCRE 8.40 allows remote attackers to cause a denial of service (invalid memory read) via a crafted file.
Scope: local
bookworm: resolved (fixed in 2:8.39-3)
bullseye: resolved (fixed in 2:8.39-3)
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2017-7244 CVE-2017-7245 CVE-2017-7246 mingw-glib2: various flaws [fedora-all]
bugzilla·2017-03-30·CVSS 5.5
CVE-2017-7244 [MEDIUM] CVE-2017-7244 CVE-2017-7245 CVE-2017-7246 mingw-glib2: various flaws [fedora-all]
CVE-2017-7244 CVE-2017-7245 CVE-2017-7246 mingw-glib2: various flaws [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple supported vers
Bugzilla
CVE-2017-7244 CVE-2017-7245 CVE-2017-7246 mingw-pcre: various flaws [fedora-all]
bugzilla·2017-03-30·CVSS 5.5
CVE-2017-7244 [MEDIUM] CVE-2017-7244 CVE-2017-7245 CVE-2017-7246 mingw-pcre: various flaws [fedora-all]
CVE-2017-7244 CVE-2017-7245 CVE-2017-7246 mingw-pcre: various flaws [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple supported versi
Bugzilla
CVE-2017-7245 pcre: stack-based buffer overflow write in pcre32_copy_substring
bugzilla·2017-03-30·CVSS 5.5
CVE-2017-7245 [MEDIUM] CVE-2017-7245 pcre: stack-based buffer overflow write in pcre32_copy_substring
CVE-2017-7245 pcre: stack-based buffer overflow write in pcre32_copy_substring
A stack-based buffer overflow flaw was found in PCRE. An attacker could use a crafted file that, when processed by PCRE, would crash the application using the PCRE library.
This issue only affects the PCRE version 8.40.
Discussion:
Created pcre tracking bugs for this issue:
Affects: fedora-all [bug 1437368]
---
External References:
https://blogs.gentoo.org/ago/2017/03/20/libpcre-two-stack-based-buffer-overflow-write-in-pcre32_copy_substring-pcre_get-c/
---
Upstream report .
---
According to the upstream report, this issue (along with CVE-2017-7244 and CVE-2017-7246) was fixed with:
commit 8037f71d03b3cd8919248f38448a0a2d3715c18c
Author: ph10
Date: Fri Feb 24 17:30:30 2017 +0000
Fix Unicode property
Bugzilla
CVE-2017-7244 CVE-2017-7245 CVE-2017-7246 glib2: various flaws [fedora-all]
bugzilla·2017-03-30·CVSS 5.5
CVE-2017-7244 [MEDIUM] CVE-2017-7244 CVE-2017-7245 CVE-2017-7246 glib2: various flaws [fedora-all]
CVE-2017-7244 CVE-2017-7245 CVE-2017-7246 glib2: various flaws [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple supported versions o
Bugzilla
CVE-2017-7246 pcre: stack-based buffer overflow write in pcre32_copy_substring
bugzilla·2017-03-30·CVSS 5.5
CVE-2017-7246 [MEDIUM] CVE-2017-7246 pcre: stack-based buffer overflow write in pcre32_copy_substring
CVE-2017-7246 pcre: stack-based buffer overflow write in pcre32_copy_substring
A stack-based buffer overflow flaw was found in PCRE. An attacker could use a crafted file that, when processed by PCRE, would crash the application using the PCRE library.
This issue only affects the PCRE version 8.40.
Discussion:
Created pcre tracking bugs for this issue:
Affects: fedora-all [bug 1437370]
---
External References:
https://blogs.gentoo.org/ago/2017/03/20/libpcre-two-stack-based-buffer-overflow-write-in-pcre32_copy_substring-pcre_get-c/
---
Upstream report .
---
According to the upstream report, this issue (along with CVE-2017-7244 and CVE-2017-7245) was fixed with:
commit 8037f71d03b3cd8919248f38448a0a2d3715c18c
Author: ph10
Date: Fri Feb 24 17:30:30 2017 +0000
Fix Unicode property
Bugzilla
CVE-2017-7244 pcre: invalid memory read in _pcre32_xclass (pcre_xclass.c)
bugzilla·2017-03-30·CVSS 5.5
CVE-2017-7244 [MEDIUM] CVE-2017-7244 pcre: invalid memory read in _pcre32_xclass (pcre_xclass.c)
CVE-2017-7244 pcre: invalid memory read in _pcre32_xclass (pcre_xclass.c)
An invalid memory read flaw was found in PCRE. An attacker could use a crafted file that, when processed by PCRE, would crash the application using the PCRE library.
Discussion:
Created pcre tracking bugs for this issue:
Affects: fedora-all [bug 1437365]
---
External References:
https://blogs.gentoo.org/ago/2017/03/20/libpcre-invalid-memory-read-in-_pcre32_xclass-pcre_xclass-c/
---
The Gentoo developer reported it to the upstream at which turns to be a duplicate of that was fixed by upstream in SVN revision 1688 with this commit:
commit 8037f71d03b3cd8919248f38448a0a2d3715c18c
Author: ph10
Date: Fri Feb 24 17:30:30 2017 +0000
Fix Unicode property crash for 32-bit characters greater than 0x10ffff.
git-svn
Bugzilla
CVE-2017-7244 CVE-2017-7245 CVE-2017-7246 mingw-glib2: various flaws [epel-7]
bugzilla·2017-03-30·CVSS 5.5
CVE-2017-7244 [MEDIUM] CVE-2017-7244 CVE-2017-7245 CVE-2017-7246 mingw-glib2: various flaws [epel-7]
CVE-2017-7244 CVE-2017-7245 CVE-2017-7246 mingw-glib2: various flaws [epel-7]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of epel-7.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
Discussion:
Use the following template to for the 'fedp
Bugzilla
CVE-2017-7244 pcre: invalid memory read in _pcre32_xclass (pcre_xclass.c) [fedora-all]
bugzilla·2017-03-30·CVSS 5.5
CVE-2017-7244 [MEDIUM] CVE-2017-7244 pcre: invalid memory read in _pcre32_xclass (pcre_xclass.c) [fedora-all]
CVE-2017-7244 pcre: invalid memory read in _pcre32_xclass (pcre_xclass.c) [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple supported ver
Bugzilla
CVE-2017-7244 CVE-2017-7245 CVE-2017-7246 mingw-pcre: various flaws [epel-7]
bugzilla·2017-03-30·CVSS 5.5
CVE-2017-7244 [MEDIUM] CVE-2017-7244 CVE-2017-7245 CVE-2017-7246 mingw-pcre: various flaws [epel-7]
CVE-2017-7244 CVE-2017-7245 CVE-2017-7246 mingw-pcre: various flaws [epel-7]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of epel-7.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
Discussion:
Use the following template to for the 'fedpk
http://www.securityfocus.com/bid/97067https://access.redhat.com/errata/RHSA-2018:2486https://blogs.gentoo.org/ago/2017/03/20/libpcre-invalid-memory-read-in-_pcre32_xclass-pcre_xclass-c/https://security.gentoo.org/glsa/201710-25http://www.securityfocus.com/bid/97067https://access.redhat.com/errata/RHSA-2018:2486https://blogs.gentoo.org/ago/2017/03/20/libpcre-invalid-memory-read-in-_pcre32_xclass-pcre_xclass-c/https://security.gentoo.org/glsa/201710-25
2017-03-23
Published