VDB
CVE-2020-14155
CVE-2020-14155
PUBLISHED
CVSS 5.300000190734863 MEDIUM
libpcre in PCRE before 8.44 allows an integer overflow via a large number after a (?C substring.
EPSS 4.18% · 90.3th percentile
Risk Scores
CVSS 3.1
5.300000190734863
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
EPSS Score
4.18%
90.3th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Bitnami | gitlab | 13.0.0, 13.1.0, 0 |
| Bitnami | gitlab | 0, 13.0.0, 13.1.0 |
Timeline
- Jun 15, 2020 CVE Published
- Apr 14, 2021 EPSS Score
- Jun 23, 2021 EPSS Score
- Oct 26, 2021 EPSS Score
- Dec 28, 2021 EPSS Score
- Jan 6, 2022 EPSS Score
- Feb 4, 2022 EPSS Score
- Apr 1, 2022 EPSS Score
- May 2, 2022 EPSS Score
- Jul 4, 2022 EPSS Score
- Sep 5, 2022 EPSS Score
- Jan 9, 2023 EPSS Score
References
- http://seclists.org/fulldisclosure/2020/Dec/32 url
- http://seclists.org/fulldisclosure/2021/Feb/14 url
- https://about.gitlab.com/releases/2020/07/01/security-release-13-1-2-release/ url
- https://bugs.gentoo.org/717920 url
- https://lists.apache.org/thread.html/rf9fa47ab66495c78bb4120b0754dd9531ca2ff0430f6685ac9b07772%40%3Cdev.mina.apache.org%3E url
- https://security.netapp.com/advisory/ntap-20221028-0010/ url
- https://support.apple.com/kb/HT211931 url
- https://support.apple.com/kb/HT212147 url
- https://www.oracle.com/security-alerts/cpuapr2022.html url
- https://www.pcre.org/original/changelog.txt url
- https://nvd.nist.gov/vuln/detail/CVE-2020-14155 url