NVD

Id
28549  
Name
CVE-2015-8381  
Description
The compile_regex function in pcre_compile.c in PCRE before 8.38 and pcre2_compile.c in PCRE2 before 10.2x mishandles the /(?J:(?|(:(?|(?"R")(k"R")|((?"R")))H"Rk"Rf)|s(?"R"))))/ and /(?J:(?|(:(?|(?"R")(z(?|(?"R")(k"R")|((?"R")))k"R")|((?"R")))H"Ak"Rf)|s(?"R")))/ patterns, and related patterns with certain group references, which allows remote attackers to cause a denial of service (heap-based buffer overflow) or possibly have unspecified other impact via a crafted regular expression, as demonstrated by a JavaScript RegExp object encountered by Konqueror.  
Reject
 
CVSS Version
2  
CVSS Score
7.5  
Severity
High  
CVSS Base Score
7.5  
CVSS Impact Subscore
6.4  
CVSS Exploit Subscore
10  
CVSS Vector
(AV:N/AC:L/Au:N/C:P/I:P/A:P)  
Pub Date
2017-01-19  
Published
2015-12-01  
Modified Date
2016-12-29  
Seq
2015-8381  

Actions