Debian Pcre3 vulnerabilities
47 known vulnerabilities affecting debian/pcre3.
Total CVEs
47
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL9HIGH12MEDIUM11LOW15
Vulnerabilities
Page 3 of 3
CVE-2017-7244P4MEDIUMCVSS 5.5fixed in pcre3 2:8.39-3 (bookworm)2017
CVE-2017-7244 [MEDIUM] CVE-2017-7244: pcre3 - The _pcre32_xclass function in pcre_xclass.c in libpcre1 in PCRE 8.40 allows rem...
The _pcre32_xclass function in pcre_xclass.c in libpcre1 in PCRE 8.40 allows remote attackers to cause a denial of service (invalid memory read) via a crafted file.
Scope: local
bookworm: resolved (fixed in 2:8.39-3)
bullseye: resolved (fixed in 2:8.39-3)
debian
CVE-2015-2326P4MEDIUMCVSS 5.5fixed in pcre3 2:8.35-7.2 (bookworm)2015
CVE-2015-2326 [MEDIUM] CVE-2015-2326: pcre3 - The pcre_compile2 function in PCRE before 8.37 allows context-dependent attacker...
The pcre_compile2 function in PCRE before 8.37 allows context-dependent attackers to compile incorrect code and cause a denial of service (out-of-bounds read) via regular expression with a group containing both a forward referencing subroutine call and a recursive back reference, as demonstrated by "((?+1)(\1))/".
Scope: local
bookworm: resolved (fixed in 2:8.35-7.2)
debian
CVE-2006-7230P4MEDIUMCVSS 4.3fixed in pcre3 7.0-1 (bookworm)2006
CVE-2006-7230 [MEDIUM] CVE-2006-7230: pcre3 - Perl-Compatible Regular Expression (PCRE) library before 7.0 does not properly c...
Perl-Compatible Regular Expression (PCRE) library before 7.0 does not properly calculate the amount of memory needed for a compiled regular expression pattern when the (1) -x or (2) -i UTF-8 options change within the pattern, which allows context-dependent attackers to cause a denial of service (PCRE or glibc crash) via crafted regular expressions.
Scope: local
bookwo
debian
CVE-2007-1662P4LOWCVSS 5.0fixed in glib2.0 2.14.3-1 (bookworm)2007
CVE-2007-1662 [MEDIUM] CVE-2007-1662: glib2.0 - Perl-Compatible Regular Expression (PCRE) library before 7.3 reads past the end ...
Perl-Compatible Regular Expression (PCRE) library before 7.3 reads past the end of the string when searching for unmatched brackets and parentheses, which allows context-dependent attackers to cause a denial of service (crash), possibly involving forward references.
Scope: local
bookworm: resolved (fixed in 2.14.3-1)
bullseye: resolved (fixed in 2.14.3-1)
forky: res
debian
CVE-2006-7226P4LOWCVSS 4.3fixed in glib2.0 2.14.3-1 (bookworm)2006
CVE-2006-7226 [MEDIUM] CVE-2006-7226: glib2.0 - Perl-Compatible Regular Expression (PCRE) library before 6.7 does not properly c...
Perl-Compatible Regular Expression (PCRE) library before 6.7 does not properly calculate the compiled memory allocation for regular expressions that involve a quantified "subpattern containing a named recursion or subroutine reference," which allows context-dependent attackers to cause a denial of service (error or crash).
Scope: local
bookworm: resolved (fixed in 2
debian
CVE-2005-4872P4MEDIUMCVSS 4.3fixed in pcre3 6.2-1 (bookworm)2005
CVE-2005-4872 [MEDIUM] CVE-2005-4872: pcre3 - Perl-Compatible Regular Expression (PCRE) library before 6.2 does not properly c...
Perl-Compatible Regular Expression (PCRE) library before 6.2 does not properly count the number of named capturing subpatterns, which allows context-dependent attackers to cause a denial of service (crash) via a regular expression with a large number of named subpatterns, which triggers a buffer overflow. NOTE: this issue was originally subsumed by CVE-2006-7224, but
debian
CVE-2006-7225P4LOWCVSS 4.3fixed in glib2.0 2.14.3-1 (bookworm)2006
CVE-2006-7225 [MEDIUM] CVE-2006-7225: glib2.0 - Perl-Compatible Regular Expression (PCRE) library before 6.7 allows context-depe...
Perl-Compatible Regular Expression (PCRE) library before 6.7 allows context-dependent attackers to cause a denial of service (error or crash) via a regular expression that involves a "malformed POSIX character class", as demonstrated via an invalid character after a [[ sequence.
Scope: local
bookworm: resolved (fixed in 2.14.3-1)
bullseye: resolved (fixed in 2.14.3-
debian
← Previous3 / 3