VYPR
High severity7.5NVD Advisory· Published Feb 16, 2017· Updated May 13, 2026

CVE-2017-6004

CVE-2017-6004

Description

The compile_bracket_matchingpath function in pcre_jit_compile.c in PCRE through 8.x before revision 1680 (e.g., the PHP 7.1.1 bundled version) allows remote attackers to cause a denial of service (out-of-bounds read and application crash) via a crafted regular expression.

Affected products

1
  • cpe:2.3:a:pcre:pcre:*:*:*:*:*:*:*:*
    Range: <=8.38

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

8

News mentions

0

No linked articles in our index yet.