Unrated severityNVD Advisory· Published Jan 14, 2020· Updated Aug 6, 2024
CVE-2015-2326
CVE-2015-2326
Description
The pcre_compile2 function in PCRE before 8.37 allows context-dependent attackers to compile incorrect code and cause a denial of service (out-of-bounds read) via regular expression with a group containing both a forward referencing subroutine call and a recursive back reference, as demonstrated by "((?+1)(\1))/".
Affected products
8- PCRE/PCREdescription
- osv-coords7 versionspkg:rpm/opensuse/php5&distro=openSUSE%20Tumbleweedpkg:rpm/opensuse/php7&distro=openSUSE%20Tumbleweedpkg:rpm/suse/mariadb&distro=SUSE%20Linux%20Enterprise%20Desktop%2012pkg:rpm/suse/mariadb&distro=SUSE%20Linux%20Enterprise%20Server%2012pkg:rpm/suse/mariadb&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2012pkg:rpm/suse/mariadb&distro=SUSE%20Linux%20Enterprise%20Software%20Development%20Kit%2012pkg:rpm/suse/mariadb&distro=SUSE%20Linux%20Enterprise%20Workstation%20Extension%2012
< 5.6.28-1.1+ 6 more
- (no CPE)range: < 5.6.28-1.1
- (no CPE)range: < 7.0.14-1.4
- (no CPE)range: < 10.0.20-18.1
- (no CPE)range: < 10.0.20-18.1
- (no CPE)range: < 10.0.20-18.1
- (no CPE)range: < 10.0.20-18.1
- (no CPE)range: < 10.0.20-18.1
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
4- lists.opensuse.org/opensuse-updates/2015-05/msg00014.htmlmitrex_refsource_MISC
- bugs.exim.org/show_bug.cgimitrex_refsource_MISC
- fortiguard.com/zeroday/FG-VD-15-016mitrex_refsource_MISC
- www.pcre.org/original/changelog.txtmitrex_refsource_CONFIRM
News mentions
0No linked articles in our index yet.