CVE-2015-5073

critical
New! CVE Severity Now Using CVSS v3

The calculated severity for CVEs has been updated to use CVSS v3 by default. CVEs that do not have a CVSS v3 score will fall back CVSS v2 for calculating severity. Severity display preferences can be toggled in the settings dropdown.

Description

Heap-based buffer overflow in the find_fixedlength function in pcre_compile.c in PCRE before 8.38 allows remote attackers to cause a denial of service (crash) or obtain sensitive information from heap memory and possibly bypass the ASLR protection mechanism via a crafted regular expression with an excess closing parenthesis.

References

http://rhn.redhat.com/errata/RHSA-2016-1025.html

http://rhn.redhat.com/errata/RHSA-2016-2750.html

http://vcs.pcre.org/pcre/code/trunk/ChangeLog?revision=1609&view=markup

http://vcs.pcre.org/pcre?view=revision&revision=1571

http://www.openwall.com/lists/oss-security/2015/06/26/1

http://www.openwall.com/lists/oss-security/2015/06/26/3

http://www.oracle.com/technetwork/topics/security/linuxbulletinapr2016-2952096.html

http://www.securityfocus.com/bid/75430

http://www.securitytracker.com/id/1033154

http://www-01.ibm.com/support/docview.wss?uid=isg3T1023886

https://access.redhat.com/errata/RHSA-2016:1132

https://bugs.exim.org/show_bug.cgi?id=1651

https://security.gentoo.org/glsa/201607-02

Details

Source: MITRE

Published: 2016-12-13

Updated: 2018-05-18

Type: CWE-119

Risk Information

CVSS v2

Base Score: 6.4

Vector: AV:N/AC:L/Au:N/C:P/I:N/A:P

Impact Score: 4.9

Exploitability Score: 10

Severity: MEDIUM

CVSS v3

Base Score: 9.1

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H

Impact Score: 5.2

Exploitability Score: 3.9

Severity: CRITICAL

Vulnerable Software

Configuration 1

OR

cpe:2.3:a:ibm:powerkvm:2.1:*:*:*:*:*:*:*

cpe:2.3:a:ibm:powerkvm:3.1:*:*:*:*:*:*:*

Configuration 2

OR

cpe:2.3:a:pcre:pcre:*:*:*:*:*:*:*:* versions up to 8.37 (inclusive)

Tenable Plugins

View all (21 total)

IDNameProductFamilySeverity
149187EulerOS 2.0 SP3 : glib2 (EulerOS-SA-2021-1789)NessusHuawei Local Security Checks
critical
137496EulerOS 2.0 SP2 : glib2 (EulerOS-SA-2020-1654)NessusHuawei Local Security Checks
critical
125102EulerOS Virtualization 3.0.1.0 : pcre (EulerOS-SA-2019-1558)NessusHuawei Local Security Checks
critical
99786EulerOS 2.0 SP1 : pcre (EulerOS-SA-2016-1023)NessusHuawei Local Security Checks
critical
97531F5 Networks BIG-IP : PCRE library vulnerability (K17331)NessusF5 Networks Local Security Checks
critical
95915SUSE SLED12 / SLES12 Security Update : pcre (SUSE-SU-2016:3161-1)NessusSuSE Local Security Checks
critical
95754openSUSE Security Update : pcre (openSUSE-2016-1448)NessusSuSE Local Security Checks
critical
95534SUSE SLED12 / SLES12 Security Update : pcre (SUSE-SU-2016:2971-1)NessusSuSE Local Security Checks
critical
94906openSUSE Security Update : pcre (openSUSE-2016-1303)NessusSuSE Local Security Checks
critical
91983GLSA-201607-02 : libpcre: Multiple VulnerabilitiesNessusGentoo Local Security Checks
critical
91104CentOS 7 : pcre (CESA-2016:1025)NessusCentOS Local Security Checks
critical
91081Scientific Linux Security Update : pcre on SL7.x x86_64 (20160511)NessusScientific Linux Local Security Checks
critical
91078RHEL 7 : pcre (RHSA-2016:1025)NessusRed Hat Local Security Checks
critical
91072Oracle Linux 7 : pcre (ELSA-2016-1025)NessusOracle Linux Local Security Checks
critical
90306Ubuntu 12.04 LTS / 14.04 LTS / 15.10 : pcre3 vulnerabilities (USN-2943-1)NessusUbuntu Local Security Checks
critical
89647Fedora 23 : mingw-pcre-8.38-1.fc23 (2016-fd1199dbe2)NessusFedora Local Security Checks
critical
89641Fedora 22 : mingw-pcre-8.38-1.fc22 (2016-f59a8ff5d0)NessusFedora Local Security Checks
critical
85122Ubuntu 12.04 LTS / 14.04 LTS / 15.04 : pcre3 vulnerabilities (USN-2694-1)NessusUbuntu Local Security Checks
critical
84887FreeBSD : pcre -- Heap Overflow Vulnerability in find_fixedlength() (8a1d0e63-1e07-11e5-b43d-002590263bf5)NessusFreeBSD Local Security Checks
critical
84843Fedora 21 : pcre-8.35-12.fc21 (2015-11019)NessusFedora Local Security Checks
critical
84685Fedora 22 : pcre-8.37-2.fc22 (2015-11027)NessusFedora Local Security Checks
critical