CVE-2008-2371
Publication date 7 July 2008
Last updated 24 July 2024
Ubuntu priority
Description
Heap-based buffer overflow in pcre_compile.c in the Perl-Compatible Regular Expression (PCRE) library 7.7 allows context-dependent attackers to cause a denial of service (crash) or possibly execute arbitrary code via a regular expression that begins with an option and contains multiple branches.
Status
| Package | Ubuntu Release | Status |
|---|---|---|
| erlang | ||
| pcre3 | ||
| php5 | ||
Notes
jdstrand
kees did pcre3 update php5 on dapper and feisty is not vulnerable jdstrand sponsored erlang update for karmic and lucid
Patch details
| Package | Patch details |
|---|---|
| erlang |
|
| php5 |