Novell Home

CVE-2008-2371

Common Vulnerabilities and Exposures

[Previous] [Index] [Next]

Upstream information

CVE-2008-2371 at MITRE

Description

Heap-based buffer overflow in pcre_compile.c in the Perl-Compatible Regular Expression (PCRE) library 7.7 allows context-dependent attackers to cause a denial of service (crash) or possibly execute arbitrary code via a regular expression that begins with an option and contains multiple branches.

NVD CVSS v2 Base Score: 7.5 (AV:N/AC:L/Au:N/C:P/I:P/A:P)

Novell/SUSE information

Novell Bugzilla entry: 400013

SUSE Security Advisories:

List of released packages

Product(s) Fixed package version(s) References
openSUSE 10.3
  • pcre >= 7.2-14.6
  • pcre-32bit >= 7.2-14.6
  • pcre-64bit >= 7.2-14.6
  • pcre-devel >= 7.2-14.6

© 2012 Novell