Out-of-Bounds Affecting pcre3 package, versions *


low

Snyk CVSS

    Attack Complexity Low
    User Interaction Required
    Confidentiality High
    Integrity High
    Availability High
Expand this section
NVD
7.8 high
Expand this section
Red Hat
3.7 low

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk ID SNYK-DEBIAN10-PCRE3-345353
  • published 23 Mar 2017
  • disclosed 23 Mar 2017

How to fix?

There is no fixed version for Debian:10 pcre3.

NVD Description

Note: Versions mentioned in the description apply to the upstream pcre3 package.

Stack-based buffer overflow in the pcre32_copy_substring function in pcre_get.c in libpcre1 in PCRE 8.40 allows remote attackers to cause a denial of service (WRITE of size 268) or possibly have unspecified other impact via a crafted file.