CVE-2016-1283

critical
New! CVE Severity Now Using CVSS v3

The calculated severity for CVEs has been updated to use CVSS v3 by default. CVEs that do not have a CVSS v3 score will fall back CVSS v2 for calculating severity. Severity display preferences can be toggled in the settings dropdown.

Description

The pcre_compile2 function in pcre_compile.c in PCRE 8.38 mishandles the /((?:F?+(?:^(?(R)a+\"){99}-))(?J)(?'R'(?'R'<((?'RR'(?'R'\){97)?J)?J)(?'R'(?'R'\){99|(:(?|(?'R')(\k'R')|((?'R')))H'R'R)(H'R))))))/ pattern and related patterns with named subgroups, which allows remote attackers to cause a denial of service (heap-based buffer overflow) or possibly have unspecified other impact via a crafted regular expression, as demonstrated by a JavaScript RegExp object encountered by Konqueror.

References

https://bugs.exim.org/show_bug.cgi?id=1767

http://www.oracle.com/technetwork/topics/security/bulletinapr2016-2952098.html

http://www.securityfocus.com/bid/79825

http://www.slackware.com/security/viewer.php?l=slackware-security&y=2016&m=slackware-security.343110

http://lists.fedoraproject.org/pipermail/package-announce/2016-March/178193.html

http://lists.fedoraproject.org/pipermail/package-announce/2016-March/178955.html

http://www.securitytracker.com/id/1034555

https://bto.bluecoat.com/security-advisory/sa128

https://www.tenable.com/security/tns-2016-18

https://security.gentoo.org/glsa/201607-02

https://www.tenable.com/security/tns-2017-14

https://access.redhat.com/errata/RHSA-2016:1132

Details

Source: MITRE

Published: 2016-01-03

Updated: 2021-08-06

Type: CWE-119

Risk Information

CVSS v2

Base Score: 7.5

Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Impact Score: 6.4

Exploitability Score: 10

Severity: HIGH

CVSS v3

Base Score: 9.8

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Impact Score: 5.9

Exploitability Score: 3.9

Severity: CRITICAL

Vulnerable Software

Configuration 1

OR

cpe:2.3:a:pcre:pcre:8.38:*:*:*:*:*:*:*

Tenable Plugins

View all (24 total)

IDNameProductFamilySeverity
98857PHP 7.1.x < 7.1.11 Multiple VulnerabilitiesWeb Application ScanningComponent Vulnerability
critical
98845PHP 7.0.x < 7.0.25 Multiple VulnerabilitiesWeb Application ScanningComponent Vulnerability
critical
98823PHP 5.6.x < 5.6.32 Multiple VulnerabilitiesWeb Application ScanningComponent Vulnerability
critical
105865Fedora 27 : php (2017-46e8bdccef)NessusFedora Local Security Checks
critical
104706Amazon Linux AMI : php56 / php70,php71 (ALAS-2017-924)NessusAmazon Linux Local Security Checks
critical
104640Tenable SecurityCenter PHP < 5.6.32 PCRE DoSNessusMisc.
critical
104633PHP 7.1.x < 7.1.11 Multiple VulnerabilitiesNessusCGI abuses
critical
104632PHP 7.0.x < 7.0.25 Multiple VulnerabilitiesNessusCGI abuses
critical
104631PHP 5.6.x < 5.6.32 Multiple VulnerabilitiesNessusCGI abuses
critical
104451Fedora 25 : php (2017-cdaaf6ea12)NessusFedora Local Security Checks
critical
104443Fedora 26 : php (2017-0af85ae851)NessusFedora Local Security Checks
critical
104266FreeBSD : PHP -- denial of service attack (de7a2b32-bd7d-11e7-b627-d43d7e971a1b)NessusFreeBSD Local Security Checks
critical
104215Slackware 14.0 / 14.1 / 14.2 / current : php (SSA:2017-300-01)NessusSlackware Local Security Checks
critical
97893Tenable Log Correlation Engine (LCE) < 4.8.1 Multiple VulnerabilitiesNessusMisc.
critical
95915SUSE SLED12 / SLES12 Security Update : pcre (SUSE-SU-2016:3161-1)NessusSuSE Local Security Checks
critical
95754openSUSE Security Update : pcre (openSUSE-2016-1448)NessusSuSE Local Security Checks
critical
95534SUSE SLED12 / SLES12 Security Update : pcre (SUSE-SU-2016:2971-1)NessusSuSE Local Security Checks
critical
94906openSUSE Security Update : pcre (openSUSE-2016-1303)NessusSuSE Local Security Checks
critical
91983GLSA-201607-02 : libpcre: Multiple VulnerabilitiesNessusGentoo Local Security Checks
critical
91719Slackware 14.1 / current : pcre (SSA:2016-172-02)NessusSlackware Local Security Checks
critical
90336FreeBSD : pcre -- heap overflow vulnerability (497b82e0-f9a0-11e5-92ce-002590263bf5)NessusFreeBSD Local Security Checks
critical
90306Ubuntu 12.04 LTS / 14.04 LTS / 15.10 : pcre3 vulnerabilities (USN-2943-1)NessusUbuntu Local Security Checks
critical
89948Fedora 22 : pcre-8.38-3.fc22 (2016-f5af8e27ce)NessusFedora Local Security Checks
critical
89557Fedora 23 : pcre-8.38-6.fc23 (2016-65833b5dbc)NessusFedora Local Security Checks
critical