CVE-2017-8399
published 2017-05-01CVE-2017-8399: PCRE2 before 10.30 has an out-of-bounds write caused by a stack-based buffer overflow in pcre2_match.c, related to a "pattern with very many captures."
PriorityP351critical9.8CVSS 3.0
AVNACLPRNUINSUCHIHAH
EPSS
3.12%
86.3th percentile
PCRE2 before 10.30 has an out-of-bounds write caused by a stack-based buffer overflow in pcre2_match.c, related to a "pattern with very many captures."
Affected
4 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | pcre2 | — | — |
| pcre | pcre2 | < 10.30 | 10.30 |
| pcre | pcre2 | >= 0 < 10.21-1 | 10.21-1 |
| pcre | pcre2 | >= 0 < 10.31-2 | 10.31-2 |
CVSS provenance
nvdv3.09.8CRITICALCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
osv9.8CRITICAL
vendor_debian9.8LOW
vendor_redhat9.8CRITICAL
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-wrv9-5822-445x: PCRE2 before 10
ghsa_unreviewed·2022-05-14
CVE-2017-8399 [CRITICAL] CWE-119 GHSA-wrv9-5822-445x: PCRE2 before 10
PCRE2 before 10.30 has an out-of-bounds write caused by a stack-based buffer overflow in pcre2_match.c, related to a "pattern with very many captures."
OSV
CVE-2017-8399: PCRE2 before 10
osv·2017-05-01·CVSS 9.8
CVE-2017-8399 [CRITICAL] CVE-2017-8399: PCRE2 before 10
PCRE2 before 10.30 has an out-of-bounds write caused by a stack-based buffer overflow in pcre2_match.c, related to a "pattern with very many captures."
Red Hat
pcre2: Stack-based buffer overflow in pcre2_match.c
vendor_redhat·2017-03-10·CVSS 9.8
CVE-2017-8399 [CRITICAL] CWE-121 pcre2: Stack-based buffer overflow in pcre2_match.c
pcre2: Stack-based buffer overflow in pcre2_match.c
PCRE2 before 10.30 has an out-of-bounds write caused by a stack-based buffer overflow in pcre2_match.c, related to a "pattern with very many captures."
Package: pcre (Red Hat Enterprise Linux 5) - Not affected
Package: glib2 (Red Hat Enterprise Linux 6) - Not affected
Package: pcre (Red Hat Enterprise Linux 6) - Not affected
Package: glib2 (Red Hat Enterprise Linux 7) - Not affected
Package: pcre (Red Hat Enterprise Linux 7) - Not affected
Package: pcre2 (Red Hat Enterprise Linux 7) - Not affected
Package: virtuoso-opensource (Red Hat Enterprise Linux 7) - Not affected
Package: httpd (Red Hat JBoss Enterprise Web Server 1) - Not affected
Package: httpd (Red Hat JBoss Enterprise Web Server 2) - Not affected
Package: pcre (Red Ha
Debian
CVE-2017-8399: pcre2 - PCRE2 before 10.30 has an out-of-bounds write caused by a stack-based buffer ove...
vendor_debian·2017·CVSS 9.8
CVE-2017-8399 [CRITICAL] CVE-2017-8399: pcre2 - PCRE2 before 10.30 has an out-of-bounds write caused by a stack-based buffer ove...
PCRE2 before 10.30 has an out-of-bounds write caused by a stack-based buffer overflow in pcre2_match.c, related to a "pattern with very many captures."
Scope: local
bookworm: resolved
bullseye: resolved
forky: resolved
sid: resolved
trixie: resolved
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2017-8399 pcre2: Stack-based buffer overflow in pcre2_match.c [fedora-all]
bugzilla·2017-05-10·CVSS 9.8
CVE-2017-8399 [CRITICAL] CVE-2017-8399 pcre2: Stack-based buffer overflow in pcre2_match.c [fedora-all]
CVE-2017-8399 pcre2: Stack-based buffer overflow in pcre2_match.c [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple supported version
Bugzilla
CVE-2017-8399 pcre2: Stack-based buffer overflow in pcre2_match.c [epel-all]
bugzilla·2017-05-10·CVSS 9.8
CVE-2017-8399 [CRITICAL] CVE-2017-8399 pcre2: Stack-based buffer overflow in pcre2_match.c [epel-all]
CVE-2017-8399 pcre2: Stack-based buffer overflow in pcre2_match.c [epel-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of epel-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple supported versions of
Bugzilla
CVE-2017-8399 pcre2: Stack-based buffer overflow in pcre2_match.c
bugzilla·2017-05-10·CVSS 9.8
CVE-2017-8399 [CRITICAL] CVE-2017-8399 pcre2: Stack-based buffer overflow in pcre2_match.c
CVE-2017-8399 pcre2: Stack-based buffer overflow in pcre2_match.c
PCRE2 before 2017-03-10 has an out-of-bounds write caused by a stack-based buffer overflow in pcre2_match.c, related to a "pattern with very many captures."
Bug report:
https://bugs.chromium.org/p/oss-fuzz/issues/detail?id=783
Upstream patch:
https://vcs.pcre.org/pcre2?view=revision&revision=674
Discussion:
Created pcre2 tracking bugs for this issue:
Affects: epel-all [bug 1449630]
Affects: fedora-all [bug 1449631]
---
Are you sure this the right commit? The r674 commit is from 2017-03-22. I also enabled the fuzzer support but running ./pcre2test with the linked reproducer does not show any crashes or abortions.
---
(In reply to Petr Pisar from comment #2)
> Are you sure this the right commit? The r674 commit is
http://www.securityfocus.com/bid/98315https://bugs.chromium.org/p/oss-fuzz/issues/detail?id=783https://security.gentoo.org/glsa/201710-09https://vcs.pcre.org/pcre2/code/tags/pcre2-10.30/ChangeLog?revision=854&view=markuphttps://vcs.pcre.org/pcre2?view=revision&revision=674http://www.securityfocus.com/bid/98315https://bugs.chromium.org/p/oss-fuzz/issues/detail?id=783https://security.gentoo.org/glsa/201710-09https://vcs.pcre.org/pcre2/code/tags/pcre2-10.30/ChangeLog?revision=854&view=markuphttps://vcs.pcre.org/pcre2?view=revision&revision=674
2017-05-01
Published