Security Advisory

CVE-2015-3217

CVE vulnerability detail — eXtreme Datacenter Security Operations

Published 2016-12-13 16:00:00
Last updated 2024-08-06 05:39:31
Assigner redhat
State PUBLISHED

Description

PCRE 7.8 and 8.32 through 8.37, and PCRE2 10.10 mishandle group empty matches, which might allow remote attackers to cause a denial of service (stack-based buffer overflow) via a crafted regular expression, as demonstrated by /^(?:(?(1).|([^W_])?)+)+$/.