Description
Heap-based buffer overflow in pcre_compile.c in the Perl-Compatible Regular Expression (PCRE) library 7.7 allows context-dependent attackers to cause a denial of service (crash) or possibly execute arbitrary code via a regular expression that begins with an option and contains multiple branches.
References (45)
Core 45
Core References
Third Party Advisory vendor-advisory
x_refsource_fedora
https://www.redhat.com/archives/fedora-package-announce/2008-July/msg00105.html
Permissions Required, Third Party Advisory vdb-entry
x_refsource_vupen
http://www.vupen.com/english/advisories/2010/0833
Permissions Required, Third Party Advisory vdb-entry
x_refsource_vupen
http://www.vupen.com/english/advisories/2008/2005
Broken Link, Third Party Advisory vendor-advisory
x_refsource_mandriva
http://www.mandriva.com/security/advisories?name=MDVSA-2008:147
Not Applicable third-party-advisory
x_refsource_secunia
http://secunia.com/advisories/32746
Exploit, Issue Tracking x_refsource_confirm
http://bugs.gentoo.org/show_bug.cgi?id=228091
Issue Tracking, Third Party Advisory vendor-advisory
x_refsource_hp
http://marc.info/?l=bugtraq&m=125631037611762&w=2
Third Party Advisory x_refsource_confirm
http://support.apple.com/kb/HT3549
Permissions Required, Third Party Advisory vdb-entry
x_refsource_vupen
http://www.vupen.com/english/advisories/2008/2006
Third Party Advisory vendor-advisory
x_refsource_gentoo
http://security.gentoo.org/glsa/glsa-200811-05.xml
Issue Tracking, Third Party Advisory vendor-advisory
x_refsource_hp
http://marc.info/?l=bugtraq&m=124654546101607&w=2
Third Party Advisory, VDB Entry vdb-entry
x_refsource_bid
http://www.securityfocus.com/bid/31681
Not Applicable third-party-advisory
x_refsource_secunia
http://secunia.com/advisories/30972
Third Party Advisory vendor-advisory
x_refsource_ubuntu
http://ubuntu.com/usn/usn-624-2
Not Applicable third-party-advisory
x_refsource_secunia
http://secunia.com/advisories/32454
Not Applicable third-party-advisory
x_refsource_secunia
http://secunia.com/advisories/30944
Not Applicable third-party-advisory
x_refsource_secunia
http://secunia.com/advisories/30958
Not Applicable third-party-advisory
x_refsource_secunia
http://secunia.com/advisories/35074
Third Party Advisory vendor-advisory
x_refsource_ubuntu
http://www.ubuntu.com/usn/usn-628-1
Not Applicable third-party-advisory
x_refsource_secunia
http://secunia.com/advisories/39300
Third Party Advisory x_refsource_confirm
http://ftp.gnome.org/pub/GNOME/sources/glib/2.16/glib-2.16.4.changes
Third Party Advisory vendor-advisory
x_refsource_ubuntu
http://www.ubuntu.com/usn/usn-624-1
Mailing List vendor-advisory
x_refsource_apple
http://lists.apple.com/archives/security-announce/2009/May/msg00002.html
Not Applicable third-party-advisory
x_refsource_secunia
http://secunia.com/advisories/30967
Third Party Advisory vendor-advisory
x_refsource_fedora
https://www.redhat.com/archives/fedora-package-announce/2008-July/msg00123.html
Broken Link, Third Party Advisory vendor-advisory
x_refsource_mandriva
http://www.mandriva.com/security/advisories?name=MDVSA-2009:023
Not Applicable third-party-advisory
x_refsource_secunia
http://secunia.com/advisories/31200
Not Applicable third-party-advisory
x_refsource_secunia
http://secunia.com/advisories/30916
Not Applicable third-party-advisory
x_refsource_secunia
http://secunia.com/advisories/32222
Not Applicable third-party-advisory
x_refsource_secunia
http://secunia.com/advisories/30961
Mailing List, Third Party Advisory vendor-advisory
x_refsource_suse
http://lists.opensuse.org/opensuse-security-announce/2008-07/msg00001.html
Third Party Advisory, VDB Entry vdb-entry
x_refsource_bid
http://www.securityfocus.com/bid/30087
Not Applicable third-party-advisory
x_refsource_secunia
http://secunia.com/advisories/30990
Third Party Advisory, US Government Resource third-party-advisory
x_refsource_cert
http://www.us-cert.gov/cas/techalerts/TA09-133A.html
Broken Link, Third Party Advisory x_refsource_confirm
http://wiki.rpath.com/wiki/Advisories:rPSA-2008-0305
Permissions Required, Third Party Advisory vdb-entry
x_refsource_vupen
http://www.vupen.com/english/advisories/2009/1297
Third Party Advisory vendor-advisory
x_refsource_debian
http://www.debian.org/security/2008/dsa-1602
Permissions Required, Third Party Advisory vdb-entry
x_refsource_vupen
http://www.vupen.com/english/advisories/2008/2336
Permissions Required, Third Party Advisory vdb-entry
x_refsource_vupen
http://www.vupen.com/english/advisories/2008/2780
Not Applicable third-party-advisory
x_refsource_secunia
http://secunia.com/advisories/30945
Third Party Advisory vendor-advisory
x_refsource_gentoo
http://www.gentoo.org/security/en/glsa/glsa-200807-03.xml
Mailing List vendor-advisory
x_refsource_apple
http://lists.apple.com/archives/security-announce/2008/Oct/msg00001.html
Third Party Advisory x_refsource_confirm
http://support.apple.com/kb/HT3216
Third Party Advisory, VDB Entry mailing-list
x_refsource_bugtraq
http://www.securityfocus.com/archive/1/497828/100/0/threaded
Not Applicable third-party-advisory
x_refsource_secunia
http://secunia.com/advisories/35650
Scores
EPSS
0.0413
EPSS Percentile
88.8%
Details
CWE
CWE-787
Status
published
Products (11)
canonical/ubuntu_linux
6.06
canonical/ubuntu_linux
7.04
canonical/ubuntu_linux
7.10
canonical/ubuntu_linux
8.04
canonical/ubuntu_linux
9.10
debian/debian_linux
4.0
fedoraproject/fedora
8
fedoraproject/fedora
9
opensuse/opensuse
10.3
pcre/pcre
7.7
... and 1 more
Published
Jul 07, 2008
Tracked Since
Feb 18, 2026