Back

MEDIUM

WebKit: Integer overflow in the PCRE regular expression compiler

Published Apr 17, 2008

Description

Integer overflow in the PCRE regular expression compiler (JavaScriptCore/pcre/pcre_compile.cpp) in Apple WebKit, as used in Safari before 3.1.1, allows remote attackers to execute arbitrary code via a regular expression with large, nested repetition counts, which triggers a heap-based buffer overflow.

Affected products

Remediation

Red Hat statement

Not vulnerable. This issue did not affect versions of pcre as shipped with Red Hat Enterprise Linux 2.1, 3, 4, or 5.

Metrics

References (17)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Apr 17, 2008
Updated Aug 7, 2024
Reserved Feb 26, 2008
NVD
Status Modified
Modified Jun 16, 2026
Red Hat
Severity Critical
Public date Mar 28, 2008