Improper resource allocation - Buffer overflow In pcre.symbols
Description
Heap-based buffer overflow in PCRE 8.34 through 8.37 and PCRE2 10.10 allows remote attackers to execute arbitrary code via a crafted regular expression, as demonstrated by /^(?P=B)((?P=B)(?J:(?Pc)(?Pa(?P=B)))>WGXCREDITS)/, a different vulnerability than CVE-2015-8384.
Mitigation
Update Impact
Minimal update. May introduce new vulnerabilities or breaking changes.
Ecosystem | Package | Affected version | Patched versions |
|---|---|---|---|
nuget | - | ||
debian 11 | 2:8.35-7.2 | ||
debian 12 | 2:8.35-7.2 |
Aliases
1. 2. 3. 4. 5. 6.