pcre: heap overflow caused by incorrect option handling
Published Jul 7, 2008
7.5
HIGHCVSS 2.0
EPSS 6.73%
Description
Heap-based buffer overflow in pcre_compile.c in the Perl-Compatible Regular Expression (PCRE) library 7.7 allows context-dependent attackers to cause a denial of service (crash) or possibly execute arbitrary code via a regular expression that begins with an option and contains multiple branches.
Affected products
No data.
Configuration 3
- 4.0
Configuration 4
- 6.06
- 7.04
- 7.10
- 8.04
- 9.10
Configuration 5
- 8
- 9
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
Red Hat statement
Not vulnerable. This issue did not affect the versions of PCRE as shipped with Red Hat Enterprise Linux 2.1, 3, 4, or 5.
Metrics
No CVSS v4.0 score for this CVE.
No CVSS v3.1 score for this CVE.
No CVSS v3.0 score for this CVE.
AV:N/AC:L/Au:N/C:P/I:P/A:P
This CVE is not in the KEV list.
No CISA SSVC assessment for this CVE yet.
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 1, 2026.
Score over time
2022–2026- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Percentile over time
- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Table of values (12 key points)
Flat stretches are collapsed; showing up to 120 newest points.
| Date | Score | Percentile | Model |
|---|---|---|---|
| Oct 1, 2026 | 6.73% (0.06726) | 93.74th | v5 (v2026.06.15) |
| Jun 15, 2026 | 6.73% (0.06726) | 93.08th | v5 (v2026.06.15) |
| Mar 17, 2025 | 3.38% (0.03382) | 86.55th | v4 (v2025.03.14) |
| Dec 17, 2024 | 4.21% (0.04215) | 92.15th | v3 (v2023.03.01) |
| Feb 21, 2024 | 0.36% (0.00363) | 71.63th | v3 (v2023.03.01) |
| Feb 8, 2024 | 0.28% (0.00277) | 67.34th | v3 (v2023.03.01) |
| Mar 7, 2023 | 0.28% (0.00277) | 63.24th | v3 (v2023.03.01) |
| Mar 6, 2023 | 4.23% (0.04229) | 87.47th | v2 (v2022.01.01) |
| Feb 13, 2023 | 4.23% (0.04229) | 87.08th | v2 (v2022.01.01) |
| Feb 3, 2023 | 2.69% (0.02686) | 82.44th | v2 (v2022.01.01) |
| Apr 1, 2022 | 4.23% (0.04229) | 86.19th | v2 (v2022.01.01) |
| Feb 4, 2022 | 4.23% (0.04229) | 69.94th | v2 (v2022.01.01) |
References (49)
- http://bugs.gentoo.org/show_bug.cgi?id=228091 x_refsource_CONFIRMExploitIssue Tracking
- http://ftp.gnome.org/pub/GNOME/sources/glib/2.16/glib-2.16.4.changes x_refsource_CONFIRMThird Party Advisory
- http://lists.apple.com/archives/security-announce/2008/Oct/msg00001.html vendor-advisoryx_refsource_APPLEMailing List
- http://lists.apple.com/archives/security-announce/2009/May/msg00002.html vendor-advisoryx_refsource_APPLEMailing List
- http://lists.opensuse.org/opensuse-security-announce/2008-07/msg00001.html vendor-advisoryx_refsource_SUSEMailing ListThird Party Advisory
- http://marc.info/?l=bugtraq&m=124654546101607&w=2 vendor-advisoryx_refsource_HPIssue TrackingThird Party Advisory
- http://marc.info/?l=bugtraq&m=125631037611762&w=2 vendor-advisoryx_refsource_HPIssue TrackingThird Party Advisory
- http://secunia.com/advisories/30916 third-party-advisoryx_refsource_SECUNIANot Applicable
- http://secunia.com/advisories/30944 third-party-advisoryx_refsource_SECUNIANot Applicable
- http://secunia.com/advisories/30945 third-party-advisoryx_refsource_SECUNIANot Applicable
- http://secunia.com/advisories/30958 third-party-advisoryx_refsource_SECUNIANot Applicable
- http://secunia.com/advisories/30961 third-party-advisoryx_refsource_SECUNIANot Applicable
- http://secunia.com/advisories/30967 third-party-advisoryx_refsource_SECUNIANot Applicable
- http://secunia.com/advisories/30972 third-party-advisoryx_refsource_SECUNIANot Applicable
- http://secunia.com/advisories/30990 third-party-advisoryx_refsource_SECUNIANot Applicable
- http://secunia.com/advisories/31200 third-party-advisoryx_refsource_SECUNIANot Applicable
- http://secunia.com/advisories/32222 third-party-advisoryx_refsource_SECUNIANot Applicable
- http://secunia.com/advisories/32454 third-party-advisoryx_refsource_SECUNIANot Applicable
- http://secunia.com/advisories/32746 third-party-advisoryx_refsource_SECUNIANot Applicable
- http://secunia.com/advisories/35074 third-party-advisoryx_refsource_SECUNIANot Applicable
- http://secunia.com/advisories/35650 third-party-advisoryx_refsource_SECUNIANot Applicable
- http://secunia.com/advisories/39300 third-party-advisoryx_refsource_SECUNIANot Applicable
- http://security.gentoo.org/glsa/glsa-200811-05.xml vendor-advisoryx_refsource_GENTOOThird Party Advisory
- http://support.apple.com/kb/HT3216 x_refsource_CONFIRMThird Party Advisory
- http://support.apple.com/kb/HT3549 x_refsource_CONFIRMThird Party Advisory
- http://ubuntu.com/usn/usn-624-2 vendor-advisoryx_refsource_UBUNTUThird Party Advisory
- http://wiki.rpath.com/wiki/Advisories:rPSA-2008-0305 x_refsource_CONFIRMBroken LinkThird Party Advisory
- http://www.debian.org/security/2008/dsa-1602 vendor-advisoryx_refsource_DEBIANThird Party Advisory
- http://www.gentoo.org/security/en/glsa/glsa-200807-03.xml vendor-advisoryx_refsource_GENTOOThird Party Advisory
- http://www.mandriva.com/security/advisories?name=MDVSA-2008:147 vendor-advisoryx_refsource_MANDRIVABroken LinkThird Party Advisory
- http://www.mandriva.com/security/advisories?name=MDVSA-2009:023 vendor-advisoryx_refsource_MANDRIVABroken LinkThird Party Advisory
- http://www.securityfocus.com/archive/1/497828/100/0/threaded mailing-listx_refsource_BUGTRAQThird Party AdvisoryVDB Entry
- http://www.securityfocus.com/bid/30087 vdb-entryx_refsource_BIDThird Party AdvisoryVDB Entry
- http://www.securityfocus.com/bid/31681 vdb-entryx_refsource_BIDThird Party AdvisoryVDB Entry
- http://www.ubuntu.com/usn/usn-624-1 vendor-advisoryx_refsource_UBUNTUThird Party Advisory
- http://www.ubuntu.com/usn/usn-628-1 vendor-advisoryx_refsource_UBUNTUThird Party Advisory
- http://www.us-cert.gov/cas/techalerts/TA09-133A.html third-party-advisoryx_refsource_CERTThird Party AdvisoryUS Government Resource
- http://www.vupen.com/english/advisories/2008/2005 vdb-entryx_refsource_VUPENPermissions RequiredThird Party Advisory
- http://www.vupen.com/english/advisories/2008/2006 vdb-entryx_refsource_VUPENPermissions RequiredThird Party Advisory
- http://www.vupen.com/english/advisories/2008/2336 vdb-entryx_refsource_VUPENPermissions RequiredThird Party Advisory
- http://www.vupen.com/english/advisories/2008/2780 vdb-entryx_refsource_VUPENPermissions RequiredThird Party Advisory
- http://www.vupen.com/english/advisories/2009/1297 vdb-entryx_refsource_VUPENPermissions RequiredThird Party Advisory
- http://www.vupen.com/english/advisories/2010/0833 vdb-entryx_refsource_VUPENPermissions RequiredThird Party Advisory
- https://access.redhat.com/security/cve/CVE-2008-2371 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=452079 Issue Tracking
- https://nvd.nist.gov/vuln/detail/CVE-2008-2371
- https://www.cve.org/CVERecord?id=CVE-2008-2371
- https://www.redhat.com/archives/fedora-package-announce/2008-July/msg00105.html vendor-advisoryx_refsource_FEDORAThird Party Advisory
- https://www.redhat.com/archives/fedora-package-announce/2008-July/msg00123.html vendor-advisoryx_refsource_FEDORAThird Party Advisory
| Link | Providers | Tags |
|---|---|---|
| http://bugs.gentoo.org/show_bug.cgi?id=228091 | x_refsource_CONFIRMExploitIssue Tracking | |
| http://ftp.gnome.org/pub/GNOME/sources/glib/2.16/glib-2.16.4.changes | x_refsource_CONFIRMThird Party Advisory | |
| http://lists.apple.com/archives/security-announce/2008/Oct/msg00001.html | vendor-advisoryx_refsource_APPLEMailing List | |
| http://lists.apple.com/archives/security-announce/2009/May/msg00002.html | vendor-advisoryx_refsource_APPLEMailing List | |
| http://lists.opensuse.org/opensuse-security-announce/2008-07/msg00001.html | vendor-advisoryx_refsource_SUSEMailing ListThird Party Advisory | |
| http://marc.info/?l=bugtraq&m=124654546101607&w=2 | vendor-advisoryx_refsource_HPIssue TrackingThird Party Advisory | |
| http://marc.info/?l=bugtraq&m=125631037611762&w=2 | vendor-advisoryx_refsource_HPIssue TrackingThird Party Advisory | |
| http://secunia.com/advisories/30916 | third-party-advisoryx_refsource_SECUNIANot Applicable | |
| http://secunia.com/advisories/30944 | third-party-advisoryx_refsource_SECUNIANot Applicable | |
| http://secunia.com/advisories/30945 | third-party-advisoryx_refsource_SECUNIANot Applicable | |
| http://secunia.com/advisories/30958 | third-party-advisoryx_refsource_SECUNIANot Applicable | |
| http://secunia.com/advisories/30961 | third-party-advisoryx_refsource_SECUNIANot Applicable | |
| http://secunia.com/advisories/30967 | third-party-advisoryx_refsource_SECUNIANot Applicable | |
| http://secunia.com/advisories/30972 | third-party-advisoryx_refsource_SECUNIANot Applicable | |
| http://secunia.com/advisories/30990 | third-party-advisoryx_refsource_SECUNIANot Applicable | |
| http://secunia.com/advisories/31200 | third-party-advisoryx_refsource_SECUNIANot Applicable | |
| http://secunia.com/advisories/32222 | third-party-advisoryx_refsource_SECUNIANot Applicable | |
| http://secunia.com/advisories/32454 | third-party-advisoryx_refsource_SECUNIANot Applicable | |
| http://secunia.com/advisories/32746 | third-party-advisoryx_refsource_SECUNIANot Applicable | |
| http://secunia.com/advisories/35074 | third-party-advisoryx_refsource_SECUNIANot Applicable | |
| http://secunia.com/advisories/35650 | third-party-advisoryx_refsource_SECUNIANot Applicable | |
| http://secunia.com/advisories/39300 | third-party-advisoryx_refsource_SECUNIANot Applicable | |
| http://security.gentoo.org/glsa/glsa-200811-05.xml | vendor-advisoryx_refsource_GENTOOThird Party Advisory | |
| http://support.apple.com/kb/HT3216 | x_refsource_CONFIRMThird Party Advisory | |
| http://support.apple.com/kb/HT3549 | x_refsource_CONFIRMThird Party Advisory | |
| http://ubuntu.com/usn/usn-624-2 | vendor-advisoryx_refsource_UBUNTUThird Party Advisory | |
| http://wiki.rpath.com/wiki/Advisories:rPSA-2008-0305 | x_refsource_CONFIRMBroken LinkThird Party Advisory | |
| http://www.debian.org/security/2008/dsa-1602 | vendor-advisoryx_refsource_DEBIANThird Party Advisory | |
| http://www.gentoo.org/security/en/glsa/glsa-200807-03.xml | vendor-advisoryx_refsource_GENTOOThird Party Advisory | |
| http://www.mandriva.com/security/advisories?name=MDVSA-2008:147 | vendor-advisoryx_refsource_MANDRIVABroken LinkThird Party Advisory | |
| http://www.mandriva.com/security/advisories?name=MDVSA-2009:023 | vendor-advisoryx_refsource_MANDRIVABroken LinkThird Party Advisory | |
| http://www.securityfocus.com/archive/1/497828/100/0/threaded | mailing-listx_refsource_BUGTRAQThird Party AdvisoryVDB Entry | |
| http://www.securityfocus.com/bid/30087 | vdb-entryx_refsource_BIDThird Party AdvisoryVDB Entry | |
| http://www.securityfocus.com/bid/31681 | vdb-entryx_refsource_BIDThird Party AdvisoryVDB Entry | |
| http://www.ubuntu.com/usn/usn-624-1 | vendor-advisoryx_refsource_UBUNTUThird Party Advisory | |
| http://www.ubuntu.com/usn/usn-628-1 | vendor-advisoryx_refsource_UBUNTUThird Party Advisory | |
| http://www.us-cert.gov/cas/techalerts/TA09-133A.html | third-party-advisoryx_refsource_CERTThird Party AdvisoryUS Government Resource | |
| http://www.vupen.com/english/advisories/2008/2005 | vdb-entryx_refsource_VUPENPermissions RequiredThird Party Advisory | |
| http://www.vupen.com/english/advisories/2008/2006 | vdb-entryx_refsource_VUPENPermissions RequiredThird Party Advisory | |
| http://www.vupen.com/english/advisories/2008/2336 | vdb-entryx_refsource_VUPENPermissions RequiredThird Party Advisory | |
| http://www.vupen.com/english/advisories/2008/2780 | vdb-entryx_refsource_VUPENPermissions RequiredThird Party Advisory | |
| http://www.vupen.com/english/advisories/2009/1297 | vdb-entryx_refsource_VUPENPermissions RequiredThird Party Advisory | |
| http://www.vupen.com/english/advisories/2010/0833 | vdb-entryx_refsource_VUPENPermissions RequiredThird Party Advisory | |
| https://access.redhat.com/security/cve/CVE-2008-2371 | Vendor Advisory | |
| https://bugzilla.redhat.com/show_bug.cgi?id=452079 | Issue Tracking | |
| https://nvd.nist.gov/vuln/detail/CVE-2008-2371 | ||
| https://www.cve.org/CVERecord?id=CVE-2008-2371 | ||
| https://www.redhat.com/archives/fedora-package-announce/2008-July/msg00105.html | vendor-advisoryx_refsource_FEDORAThird Party Advisory | |
| https://www.redhat.com/archives/fedora-package-announce/2008-July/msg00123.html | vendor-advisoryx_refsource_FEDORAThird Party Advisory |
Change history (0)
No recorded changes yet.