pcre: inefficient posix character class syntax check (8.38/16)
Published Dec 2, 2015
9.8
CRITICALCVSS 3.1
EPSS 6.40%
Description
The pcre_compile function in pcre_compile.c in PCRE before 8.38 mishandles certain [: nesting, which allows remote attackers to cause a denial of service (CPU consumption) or possibly have unspecified other impact via a crafted regular expression, as demonstrated by a JavaScript RegExp object encountered by Konqueror.
Affected products
No data.
Configuration 3
- 22
Configuration 4
- 7.0
- 7.2
- 7.3
- 7.4
- 7.5
- 7.6
- 7.7
- 7.0
- 7.2
- 7.3
- 7.4
- 7.6
- 7.7
- 7.2
- 7.3
- 7.6
- 7.7
- 7.0
No data.
Red Hat Enterprise Linux 7
pcre-0:8.32-15.el7_2.1
Fixed · RHSA-2016:1025
Red Hat Software Collections for Red Hat Enterprise Linux 6
rh-mariadb100-mariadb-1:10.0.25-4.el6
Fixed · RHSA-2016:1132
Red Hat Software Collections for Red Hat Enterprise Linux 6
rh-php56-0:2.3-1.el6
Fixed · RHSA-2016:2750
Red Hat Software Collections for Red Hat Enterprise Linux 6
rh-php56-php-0:5.6.25-1.el6
Fixed · RHSA-2016:2750
Red Hat Software Collections for Red Hat Enterprise Linux 6
rh-php56-php-pear-1:1.9.5-4.el6
Fixed · RHSA-2016:2750
Red Hat Software Collections for Red Hat Enterprise Linux 6.6 EUS
rh-mariadb100-mariadb-1:10.0.25-4.el6
Fixed · RHSA-2016:1132
Red Hat Software Collections for Red Hat Enterprise Linux 6.7 EUS
rh-mariadb100-mariadb-1:10.0.25-4.el6
Fixed · RHSA-2016:1132
Red Hat Software Collections for Red Hat Enterprise Linux 6.7 EUS
rh-php56-0:2.3-1.el6
Fixed · RHSA-2016:2750
Red Hat Software Collections for Red Hat Enterprise Linux 6.7 EUS
rh-php56-php-0:5.6.25-1.el6
Fixed · RHSA-2016:2750
Red Hat Software Collections for Red Hat Enterprise Linux 6.7 EUS
rh-php56-php-pear-1:1.9.5-4.el6
Fixed · RHSA-2016:2750
Red Hat Software Collections for Red Hat Enterprise Linux 7
rh-mariadb100-mariadb-1:10.0.25-4.el7
Fixed · RHSA-2016:1132
Red Hat Software Collections for Red Hat Enterprise Linux 7
rh-php56-0:2.3-1.el7
Fixed · RHSA-2016:2750
Red Hat Software Collections for Red Hat Enterprise Linux 7
rh-php56-php-0:5.6.25-1.el7
Fixed · RHSA-2016:2750
Red Hat Software Collections for Red Hat Enterprise Linux 7
rh-php56-php-pear-1:1.9.5-4.el7
Fixed · RHSA-2016:2750
Red Hat Software Collections for Red Hat Enterprise Linux 7.1 EUS
rh-mariadb100-mariadb-1:10.0.25-4.el7
Fixed · RHSA-2016:1132
Red Hat Software Collections for Red Hat Enterprise Linux 7.2 EUS
rh-mariadb100-mariadb-1:10.0.25-4.el7
Fixed · RHSA-2016:1132
Red Hat Software Collections for Red Hat Enterprise Linux 7.2 EUS
rh-php56-0:2.3-1.el7
Fixed · RHSA-2016:2750
Red Hat Software Collections for Red Hat Enterprise Linux 7.2 EUS
rh-php56-php-0:5.6.25-1.el7
Fixed · RHSA-2016:2750
Red Hat Software Collections for Red Hat Enterprise Linux 7.2 EUS
rh-php56-php-pear-1:1.9.5-4.el7
Fixed · RHSA-2016:2750
Red Hat Software Collections for Red Hat Enterprise Linux 7.3 EUS
rh-php56-0:2.3-1.el7
Fixed · RHSA-2016:2750
Red Hat Software Collections for Red Hat Enterprise Linux 7.3 EUS
rh-php56-php-0:5.6.25-1.el7
Fixed · RHSA-2016:2750
Red Hat Software Collections for Red Hat Enterprise Linux 7.3 EUS
rh-php56-php-pear-1:1.9.5-4.el7
Fixed · RHSA-2016:2750
Red Hat Directory Server 8
pcre
Not affected
Red Hat Enterprise Linux 5
pcre
Not affected
Red Hat Enterprise Linux 6
glib2
Not affected
Red Hat Enterprise Linux 6
pcre
Not affected
Red Hat Enterprise Linux 7
glib2
Will not fix
Red Hat Enterprise Linux 7
virtuoso-opensource
Not affected
Red Hat JBoss Enterprise Web Server 1
httpd
Not affected
Red Hat JBoss Enterprise Web Server 2
httpd
Not affected
Red Hat JBoss Enterprise Web Server 3
pcre
Will not fix
Red Hat Software Collections
php54-php
Will not fix
Red Hat Software Collections
php55-php
Will not fix
Red Hat Software Collections
rh-mariadb101-mariadb
Not affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 7 | pcre-0:8.32-15.el7_2.1 | Fixed | RHSA-2016:1025 |
| Red Hat Software Collections for Red Hat Enterprise Linux 6 | rh-mariadb100-mariadb-1:10.0.25-4.el6 | Fixed | RHSA-2016:1132 |
| Red Hat Software Collections for Red Hat Enterprise Linux 6 | rh-php56-0:2.3-1.el6 | Fixed | RHSA-2016:2750 |
| Red Hat Software Collections for Red Hat Enterprise Linux 6 | rh-php56-php-0:5.6.25-1.el6 | Fixed | RHSA-2016:2750 |
| Red Hat Software Collections for Red Hat Enterprise Linux 6 | rh-php56-php-pear-1:1.9.5-4.el6 | Fixed | RHSA-2016:2750 |
| Red Hat Software Collections for Red Hat Enterprise Linux 6.6 EUS | rh-mariadb100-mariadb-1:10.0.25-4.el6 | Fixed | RHSA-2016:1132 |
| Red Hat Software Collections for Red Hat Enterprise Linux 6.7 EUS | rh-mariadb100-mariadb-1:10.0.25-4.el6 | Fixed | RHSA-2016:1132 |
| Red Hat Software Collections for Red Hat Enterprise Linux 6.7 EUS | rh-php56-0:2.3-1.el6 | Fixed | RHSA-2016:2750 |
| Red Hat Software Collections for Red Hat Enterprise Linux 6.7 EUS | rh-php56-php-0:5.6.25-1.el6 | Fixed | RHSA-2016:2750 |
| Red Hat Software Collections for Red Hat Enterprise Linux 6.7 EUS | rh-php56-php-pear-1:1.9.5-4.el6 | Fixed | RHSA-2016:2750 |
| Red Hat Software Collections for Red Hat Enterprise Linux 7 | rh-mariadb100-mariadb-1:10.0.25-4.el7 | Fixed | RHSA-2016:1132 |
| Red Hat Software Collections for Red Hat Enterprise Linux 7 | rh-php56-0:2.3-1.el7 | Fixed | RHSA-2016:2750 |
| Red Hat Software Collections for Red Hat Enterprise Linux 7 | rh-php56-php-0:5.6.25-1.el7 | Fixed | RHSA-2016:2750 |
| Red Hat Software Collections for Red Hat Enterprise Linux 7 | rh-php56-php-pear-1:1.9.5-4.el7 | Fixed | RHSA-2016:2750 |
| Red Hat Software Collections for Red Hat Enterprise Linux 7.1 EUS | rh-mariadb100-mariadb-1:10.0.25-4.el7 | Fixed | RHSA-2016:1132 |
| Red Hat Software Collections for Red Hat Enterprise Linux 7.2 EUS | rh-mariadb100-mariadb-1:10.0.25-4.el7 | Fixed | RHSA-2016:1132 |
| Red Hat Software Collections for Red Hat Enterprise Linux 7.2 EUS | rh-php56-0:2.3-1.el7 | Fixed | RHSA-2016:2750 |
| Red Hat Software Collections for Red Hat Enterprise Linux 7.2 EUS | rh-php56-php-0:5.6.25-1.el7 | Fixed | RHSA-2016:2750 |
| Red Hat Software Collections for Red Hat Enterprise Linux 7.2 EUS | rh-php56-php-pear-1:1.9.5-4.el7 | Fixed | RHSA-2016:2750 |
| Red Hat Software Collections for Red Hat Enterprise Linux 7.3 EUS | rh-php56-0:2.3-1.el7 | Fixed | RHSA-2016:2750 |
| Red Hat Software Collections for Red Hat Enterprise Linux 7.3 EUS | rh-php56-php-0:5.6.25-1.el7 | Fixed | RHSA-2016:2750 |
| Red Hat Software Collections for Red Hat Enterprise Linux 7.3 EUS | rh-php56-php-pear-1:1.9.5-4.el7 | Fixed | RHSA-2016:2750 |
| Red Hat Directory Server 8 | pcre | Not affected | n/a |
| Red Hat Enterprise Linux 5 | pcre | Not affected | n/a |
| Red Hat Enterprise Linux 6 | glib2 | Not affected | n/a |
| Red Hat Enterprise Linux 6 | pcre | Not affected | n/a |
| Red Hat Enterprise Linux 7 | glib2 | Will not fix | n/a |
| Red Hat Enterprise Linux 7 | virtuoso-opensource | Not affected | n/a |
| Red Hat JBoss Enterprise Web Server 1 | httpd | Not affected | n/a |
| Red Hat JBoss Enterprise Web Server 2 | httpd | Not affected | n/a |
| Red Hat JBoss Enterprise Web Server 3 | pcre | Will not fix | n/a |
| Red Hat Software Collections | php54-php | Will not fix | n/a |
| Red Hat Software Collections | php55-php | Will not fix | n/a |
| Red Hat Software Collections | rh-mariadb101-mariadb | Not affected | n/a |
No package ranges for this CVE.
Remediation
No remediation recorded yet.
References (17)
- http://lists.fedoraproject.org/pipermail/package-announce/2016-January/174931.html vendor-advisoryMailing ListThird Party Advisory
- http://rhn.redhat.com/errata/RHSA-2016-1025.html vendor-advisoryThird Party Advisory
- http://rhn.redhat.com/errata/RHSA-2016-2750.html vendor-advisoryThird Party Advisory
- http://vcs.pcre.org/pcre/code/trunk/ChangeLog?view=markup Broken Link
- http://www-01.ibm.com/support/docview.wss?uid=isg3T1023886 Third Party Advisory
- http://www.openwall.com/lists/oss-security/2015/11/29/1 mailing-listMailing ListThird Party Advisory
- http://www.oracle.com/technetwork/topics/security/linuxbulletinapr2016-2952096.html Third Party Advisory
- http://www.securityfocus.com/bid/82990 vdb-entryThird Party AdvisoryVDB Entry
- https://access.redhat.com/errata/RHSA-2016:1132 vendor-advisoryThird Party Advisory
- https://access.redhat.com/security/cve/CVE-2015-8391 Vendor Advisory
- https://bto.bluecoat.com/security-advisory/sa128 Permissions Required
- https://bugzilla.redhat.com/show_bug.cgi?id=1287671 Issue Tracking
- https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c05240731 Third Party Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2015-8391
- https://security.gentoo.org/glsa/201607-02 vendor-advisoryThird Party Advisory
- https://security.netapp.com/advisory/ntap-20230216-0002/
- https://www.cve.org/CVERecord?id=CVE-2015-8391
Change history (0)
No recorded changes yet.