CVE-2008-2371

UnknownEPSS 6.73%

Last modified

CVE-2008-2371 is a vulnerability of currently unknown severity. Heap-based buffer overflow in pcre_compile.c in the Perl-Compatible Regular Expression (PCRE) library 7.7 allows context-dependent attackers to cause a denial of service (crash) or possibly execute arbitrary code via a regular expression that begins with an option and contains multiple branches.. EPSS estimates a 6.73% chance of exploitation in the next 30 days.

Description

Heap-based buffer overflow in pcre_compile.c in the Perl-Compatible Regular Expression (PCRE) library 7.7 allows context-dependent attackers to cause a denial of service (crash) or possibly execute arbitrary code via a regular expression that begins with an option and contains multiple branches.

Metrics

EPSS Probability
6.73%

93.1th percentile

Probability of exploitation in the next 30 days. Learn more

Weakness Enumeration

Affected Software

VendorProductVersions
PcrePcre7.7
PhpPhp>= 5.2.0, <= 5.2.7
DebianDebian Linux4.0
CanonicalUbuntu Linux6.06
CanonicalUbuntu Linux7.04
CanonicalUbuntu Linux7.10
CanonicalUbuntu Linux8.04
CanonicalUbuntu Linux9.10
FedoraprojectFedora8
FedoraprojectFedora9
OpensuseOpensuse10.3

References

Timeline

Published
Last Modified
Status
Modified

Frequently Asked Questions

What is CVE-2008-2371?
Heap-based buffer overflow in pcre_compile.c in the Perl-Compatible Regular Expression (PCRE) library 7.7 allows context-dependent attackers to cause a denial of service (crash) or possibly execute arbitrary code via a regular expression that begins with an option and contains multiple branches.
How severe is CVE-2008-2371?
Severity scoring for CVE-2008-2371 is pending analysis. The EPSS model estimates a 6.73% probability of exploitation in the next 30 days.
How do I fix CVE-2008-2371?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

Are you affected by CVE-2008-2371?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST