CVE-2020-14155Integer Overflow or Wraparound in Pcre

Severity
5.3MEDIUMNVD
EPSS
0.2%
top 54.17%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJun 15
Latest updateOct 15

Description

libpcre in PCRE before 8.44 allows an integer overflow via a large number after a (?C substring.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:LExploitability: 3.9 | Impact: 1.4

Affected Packages5 packages

NVDpcre/pcre< 8.44
NVDapple/macos< 11.0.1
NVDgitlab/gitlab13.0.013.0.8+2
NVDsplunk/universal_forwarder8.2.08.2.12+2

Patches

🔴Vulnerability Details

4
GHSA
GHSA-g6g8-99m5-jj82: libpcre in PCRE before 82022-05-24
OSV
pcre3 vulnerabilities2022-05-17
OSV
CVE-2020-14155: libpcre in PCRE before 82020-06-15
CVEList
CVE-2020-14155: libpcre in PCRE before 82020-06-15

📋Vendor Advisories

7
Oracle
Oracle Oracle Fusion Middleware Risk Matrix: SSL Module (PCRE) — CVE-2020-141552022-10-15
Ubuntu
PCRE vulnerabilities2022-05-17
Oracle
Oracle Oracle Communications Risk Matrix: Policy (PCRE) — CVE-2020-141552022-04-15
Apple
CVE-2020-14155: macOS Big Sur 11.2, Security Update 2021-001 Catalina, Security Update 2021-001 Mojave2021-02-01
Red Hat
pcre: Integer overflow when parsing callout numeric arguments2020-06-15

💬Community

3
Bugzilla
CVE-2020-14155 pcre: integer overflow in libpcre [fedora-all]2020-06-18
Bugzilla
CVE-2020-14155 pcre: Integer overflow when parsing callout numeric arguments2020-06-18
Bugzilla
CVE-2020-14155 mingw-pcre: pcre: integer overflow in libpcre [fedora-all]2020-06-18
CVE-2020-14155 — Integer Overflow or Wraparound in Pcre | cvebase