CVE-2006-7224: Integer Overflow
REJECT DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2006-7227, CVE-2005-4872, CVE-2006-7228. Reason: this candidate was SPLIT into other identifiers in order to reflect different affected versions and distinct vendor fixes. Notes: All CVE users should consult CVE-2006-7227, CVE-2005-4872, and CVE-2006-7228 to determine which ID is appropriate. All references and descriptions in this candidate have been removed to prevent accidental usage.
Other sources
Common Vulnerabilities and Exposures assigned an identifier CVE-2006-7224 to the following vulnerability:
Multiple integer overflows in Perl-Compatible Regular Expression (PCRE) library before 6.7 allow context-dependent attackers to execute arbitrary code via a regular expression containing (1) a large number of named subpatterns (namecount), (2) long subpattern names (maxnamesize), (3) a repeated subpattern with a long name, or (4) an unspecified vector involving the (a) max, (b) min, and (c) duplength variables in the length calculation in pcrecompile.
References:
http://scary.beasts.org/security/CESA-2007-006.html http://www.pcre.org/changelog.txt http://secunia.com/advisories/27582
— Red Hat
Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2006-7227, CVE-2005-4872, CVE-2006-7228. Reason: this candidate was SPLIT into other identifiers in order to reflect different affected versions and distinct vendor fixes. Notes: All CVE users should consult CVE-2006-7227, CVE-2005-4872, and CVE-2006-7228 to determine which ID is appropriate. All references and descriptions in this candidate have been removed to prevent accidental usage
This CVE ID has been rejected or withdrawn by its CVE Numbering Authority for the following reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2006-7227, CVE-2005-4872, CVE-2006-7228. Reason: this candidate was SPLIT into other identifiers in order to reflect different affected versions and distinct vendor fixes. Notes: All CVE users should consult CVE-2006-7227, CVE-2005-4872, and CVE-2006-7228 to determine which ID is appropriate. All references and descriptions in this candidate have been removed to prevent accidental usage
— Red Hat
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2006-7224?
CVE-2006-7224 has been rejected and is not assigned a severity due to its split into other identifiers.
How do I fix CVE-2006-7224?
Since CVE-2006-7224 has been deprecated, refer to CVE-2006-7227, CVE-2005-4872, and CVE-2006-7228 for applicable fixes.
What versions are affected by CVE-2006-7224?
The vulnerability was associated with the PCRE Library versions prior to 6.7.
Is CVE-2006-7224 still relevant for current systems?
No, CVE-2006-7224 is not relevant as it has been split into other CVE identifiers.
Where can I find more information about vulnerabilities related to CVE-2006-7224?
For more information, consult the related identifiers CVE-2006-7227, CVE-2005-4872, and CVE-2006-7228.