The pcre_exec function in pcre_exec.c in PCRE before 8.38 mishandles a // pattern with a \01 string, which allows remote attackers to cause a denial of service (heap-based buffer overflow) or possibly have unspecified other impact via a crafted regular expression, as demonstrated by a JavaScript RegExp object encountered by Konqueror.
CVSS Details
- CVSS 3.1 Base Score: 7.3
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade pcre | Aug 30, 2017 | Dec 1, 2015 |
| Debian | — | Upgrade pcre3 | Jul 30, 2024 | Dec 2, 2015 |
| F5 Big Ip | — | Update F5 BIG-IP to the latest version | Jun 17, 2026 | Feb 4, 2016 |
| Gentoo Linux | — | Upgrade dev-libs/libpcre. | Oct 30, 2017 | Dec 1, 2015 |
| Huawei Euleros 2_0_sp2 | — | Upgrade pcreUpgrade pcre-devel | Jul 23, 2019 | Dec 2, 2015 |
| Huawei Euleros 2_0_sp3 | — | Upgrade pcreUpgrade pcre-devel | Jun 28, 2018 | Dec 1, 2015 |
| Oracle Solaris | — | Upgrade library/pcre to version 8.38-0.175.3.5.0.1.0 on Solaris 11.3 | Jun 15, 2018 | Dec 1, 2015 |
| Redhat_linux | — | No solution exists | Jul 9, 2025 | Jun 1, 2015 |
| Suse | — | Upgrade libpcre1-32bitUpgrade pcre-devel-staticUpgrade pcre-develUpgrade libpcrecpp0Upgrade libpcre1Upgrade sles12-docker-imageUpgrade pcre-toolsUpgrade libpcrecpp0-32bitUpgrade libpcreposix0Upgrade libpcre16-0Upgrade sles12sp1-docker-image | Nov 15, 2016 | Dec 1, 2015 |
| Ubuntu | — | Upgrade libpcre3 | Apr 4, 2016 | Dec 1, 2015 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub