CVE-2015-3210 REJECTED

Heap-based buffer overflow in PCRE 8.34 through 8.37 and PCRE2 10.10 allows remote attackers to execute arbitrary code via a crafted regular expression, as demonstrated by /^(?P=B)((?P=B)(?J:(?P<B>c)(?P<B>a(?P=B)))>WGXCREDITS)/, a different vulnerability than CVE-2015-8384.

EPSS 5.73% · 90.4th percentile

Risk Scores

EPSS Score
5.73%
90.4th percentile

Affected Products

VendorProductVersions
Ubuntu:14.04:LTSpcre30, 1:8.31-2

Timeline

References

Open in Interactive Console →