CVE Vulnerabilities

CVE-2005-2491

Published: Aug 23, 2005 | Modified: Feb 13, 2023
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
7.5 HIGH
AV:N/AC:L/Au:N/C:P/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu

Integer overflow in pcre_compile.c in Perl Compatible Regular Expressions (PCRE) before 6.2, as used in multiple products such as Python, Ethereal, and PHP, allows attackers to execute arbitrary code via quantifier values in regular expressions, which leads to a heap-based buffer overflow.

Affected Software

Name Vendor Start Version End Version
Pcre Pcre 5.0 5.0
Pcre Pcre 6.0 6.0
Pcre Pcre 6.1 6.1

References