Heap-based buffer overflow in pcre_compile.c in the Perl-Compatible Regular Expression (PCRE) library 7.7 allows context-dependent attackers to cause a denial of service (crash) or possibly execute arbitrary code via a regular expression that begins with an option and contains multiple branches.
References
Link Providers
http://bugs.gentoo.org/show_bug.cgi?id=228091 cve-icon cve-icon
http://ftp.gnome.org/pub/GNOME/sources/glib/2.16/glib-2.16.4.changes cve-icon cve-icon
http://lists.apple.com/archives/security-announce/2008/Oct/msg00001.html cve-icon cve-icon
http://lists.apple.com/archives/security-announce/2009/May/msg00002.html cve-icon cve-icon
http://lists.opensuse.org/opensuse-security-announce/2008-07/msg00001.html cve-icon cve-icon
http://marc.info/?l=bugtraq&m=124654546101607&w=2 cve-icon cve-icon
http://marc.info/?l=bugtraq&m=125631037611762&w=2 cve-icon cve-icon
http://secunia.com/advisories/30916 cve-icon cve-icon
http://secunia.com/advisories/30944 cve-icon cve-icon
http://secunia.com/advisories/30945 cve-icon cve-icon
http://secunia.com/advisories/30958 cve-icon cve-icon
http://secunia.com/advisories/30961 cve-icon cve-icon
http://secunia.com/advisories/30967 cve-icon cve-icon
http://secunia.com/advisories/30972 cve-icon cve-icon
http://secunia.com/advisories/30990 cve-icon cve-icon
http://secunia.com/advisories/31200 cve-icon cve-icon
http://secunia.com/advisories/32222 cve-icon cve-icon
http://secunia.com/advisories/32454 cve-icon cve-icon
http://secunia.com/advisories/32746 cve-icon cve-icon
http://secunia.com/advisories/35074 cve-icon cve-icon
http://secunia.com/advisories/35650 cve-icon cve-icon
http://secunia.com/advisories/39300 cve-icon cve-icon
http://security.gentoo.org/glsa/glsa-200811-05.xml cve-icon cve-icon
http://support.apple.com/kb/HT3216 cve-icon cve-icon
http://support.apple.com/kb/HT3549 cve-icon cve-icon
http://ubuntu.com/usn/usn-624-2 cve-icon cve-icon
http://wiki.rpath.com/wiki/Advisories:rPSA-2008-0305 cve-icon cve-icon
http://www.debian.org/security/2008/dsa-1602 cve-icon cve-icon
http://www.gentoo.org/security/en/glsa/glsa-200807-03.xml cve-icon cve-icon
http://www.mandriva.com/security/advisories?name=MDVSA-2008:147 cve-icon cve-icon
http://www.mandriva.com/security/advisories?name=MDVSA-2009:023 cve-icon cve-icon
http://www.securityfocus.com/archive/1/497828/100/0/threaded cve-icon cve-icon
http://www.securityfocus.com/bid/30087 cve-icon cve-icon
http://www.securityfocus.com/bid/31681 cve-icon cve-icon
http://www.ubuntu.com/usn/usn-624-1 cve-icon cve-icon
http://www.ubuntu.com/usn/usn-628-1 cve-icon cve-icon
http://www.us-cert.gov/cas/techalerts/TA09-133A.html cve-icon cve-icon
http://www.vupen.com/english/advisories/2008/2005 cve-icon cve-icon
http://www.vupen.com/english/advisories/2008/2006 cve-icon cve-icon
http://www.vupen.com/english/advisories/2008/2336 cve-icon cve-icon
http://www.vupen.com/english/advisories/2008/2780 cve-icon cve-icon
http://www.vupen.com/english/advisories/2009/1297 cve-icon cve-icon
http://www.vupen.com/english/advisories/2010/0833 cve-icon cve-icon
https://nvd.nist.gov/vuln/detail/CVE-2008-2371 cve-icon
https://www.cve.org/CVERecord?id=CVE-2008-2371 cve-icon
https://www.redhat.com/archives/fedora-package-announce/2008-July/msg00105.html cve-icon cve-icon
https://www.redhat.com/archives/fedora-package-announce/2008-July/msg00123.html cve-icon cve-icon
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: redhat

Published: 2008-07-07T23:00:00

Updated: 2024-08-07T08:58:02.237Z

Reserved: 2008-05-21T00:00:00

Link: CVE-2008-2371

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Analyzed

Published: 2008-07-07T23:41:00.000

Modified: 2022-08-01T15:54:58.713

Link: CVE-2008-2371

cve-icon Redhat

Severity : Important

Publid Date: 2008-06-26T00:00:00Z

Links: CVE-2008-2371 - Bugzilla