High severity7.5NVD Advisory· Published Mar 20, 2017· Updated May 13, 2026
CVE-2017-7186
CVE-2017-7186
Description
libpcre1 in PCRE 8.40 and libpcre2 in PCRE2 10.23 allow remote attackers to cause a denial of service (segmentation violation for read access, and application crash) by triggering an invalid Unicode property lookup.
Affected products
2Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
10- blogs.gentoo.org/ago/2017/03/14/libpcre-invalid-memory-read-in-match-pcre_exec-c/nvdPatchThird Party Advisory
- vcs.pcre.org/pcre/code/trunk/pcre_internal.hnvdPatch
- vcs.pcre.org/pcre/code/trunk/pcre_ucd.cnvdPatch
- vcs.pcre.org/pcre2/code/trunk/src/pcre2_internal.hnvdPatch
- vcs.pcre.org/pcre2/code/trunk/src/pcre2_ucd.cnvdPatch
- bugs.exim.org/show_bug.cginvdThird Party Advisory
- www.securityfocus.com/bid/97030nvd
- access.redhat.com/errata/RHSA-2018:2486nvd
- security.gentoo.org/glsa/201710-09nvd
- security.gentoo.org/glsa/201710-25nvd
News mentions
0No linked articles in our index yet.