Integer overflow in Perl-Compatible Regular Expression (PCRE) library before 6.7 might allow context-dependent attackers to execute arbitrary code via a regular expression that involves large (1) min, (2) max, or (3) duplength values that cause an incorrect length calculation and trigger a buffer overflow, a different vulnerability than CVE-2006-7227. NOTE: this issue was originally subsumed by CVE-2006-7224, but that CVE has been REJECTED and split.
CVSS Details
- CVSS 3.1 Base Score: 5
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade pcre3 | Jul 30, 2024 | Nov 14, 2007 |
| Gentoo Linux | — | Upgrade dev-lang/python.Upgrade dev-libs/libpcre. | Oct 30, 2017 | Nov 14, 2007 |
| Oracle_linux | — | Upgrade pcreUpgrade pcre-devel | Oct 16, 2024 | Nov 14, 2007 |
| Suse | — | Upgrade python-develUpgrade python-64bitUpgrade python-xmlUpgrade python-demoUpgrade python-docUpgrade python-x86Upgrade python-tkUpgrade python-doc-pdfUpgrade python-mpzUpgrade pythonUpgrade python-cursesUpgrade python-32bitUpgrade python-gdbmUpgrade python-idle | Feb 17, 2015 | Nov 14, 2007 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub