CVE-2017-6004 PUBLISHED

The compile_bracket_matchingpath function in pcre_jit_compile.c in PCRE through 8.x before revision 1680 (e.g., the PHP 7.1.1 bundled version) allows remote attackers to cause a denial of service (out-of-bounds read and application crash) via a crafted regular expression.

EPSS 4.08% · 88.5th percentile

Risk Scores

EPSS Score
4.08%
88.5th percentile

Affected Products

VendorProductVersions
Ubuntu:Pro:16.04:LTSpcre30, 2:8.35-7.1ubuntu1, 2:8.38-1ubuntu1

Timeline

References

Open in Interactive Console →