CVE-2015-8393 PUBLISHED

pcregrep in PCRE before 8.38 mishandles the -q option for binary files, which might allow remote attackers to obtain sensitive information via a crafted file, as demonstrated by a CGI script that sends stdout data to a client.

EPSS 0.72% · 72.2th percentile

Risk Scores

EPSS Score
0.72%
72.2th percentile

Affected Products

VendorProductVersions
Ubuntu:14.04:LTSpcre30, 1:8.31-2, 1:8.31-2ubuntu2

Timeline

References

Open in Interactive Console →