7.5

CVE-2008-2371

Exploit

Heap-based buffer overflow in pcre_compile.c in the Perl-Compatible Regular Expression (PCRE) library 7.7 allows context-dependent attackers to cause a denial of service (crash) or possibly execute arbitrary code via a regular expression that begins with an option and contains multiple branches.

Data is provided by the National Vulnerability Database (NVD)
PcrePcre Version7.7
PhpPhp Version >= 5.2.0 <= 5.2.7
DebianDebian Linux Version4.0
CanonicalUbuntu Linux Version6.06
CanonicalUbuntu Linux Version7.04
CanonicalUbuntu Linux Version7.10
CanonicalUbuntu Linux Version8.04 SwEdition-
CanonicalUbuntu Linux Version9.10
FedoraprojectFedora Version8
FedoraprojectFedora Version9
OpensuseOpensuse Version10.3
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 4.13% 0.882
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 7.5 10 6.4
AV:N/AC:L/Au:N/C:P/I:P/A:P
CWE-787 Out-of-bounds Write

The product writes data past the end, or before the beginning, of the intended buffer.

http://www.us-cert.gov/cas/techalerts/TA09-133A.html
Third Party Advisory
US Government Resource
http://www.vupen.com/english/advisories/2009/1297
Third Party Advisory
Permissions Required
http://marc.info/?l=bugtraq&m=125631037611762&w=2
Third Party Advisory
Issue Tracking
http://www.securityfocus.com/bid/31681
Third Party Advisory
VDB Entry
http://www.vupen.com/english/advisories/2008/2780
Third Party Advisory
Permissions Required
http://marc.info/?l=bugtraq&m=124654546101607&w=2
Third Party Advisory
Issue Tracking
http://ubuntu.com/usn/usn-624-2
Third Party Advisory
http://www.securityfocus.com/bid/30087
Third Party Advisory
VDB Entry
http://www.vupen.com/english/advisories/2008/2005
Third Party Advisory
Permissions Required
http://www.vupen.com/english/advisories/2008/2006
Third Party Advisory
Permissions Required
http://www.vupen.com/english/advisories/2008/2336
Third Party Advisory
Permissions Required
http://www.vupen.com/english/advisories/2010/0833
Third Party Advisory
Permissions Required