CVE-2008-1026: Buffer Overflow
Published Apr 17, 2008
·Updated
Integer overflow in the PCRE regular expression compiler (JavaScriptCore/pcre/pcrecompile.cpp) in Apple WebKit, as used in Safari before 3.1.1, allows remote attackers to execute arbitrary code via a regular expression with large, nested repetition counts, which triggers a heap-based buffer overflow.
Affected Software
8 affected components
Apple iOS and macOS=10.4.11
Apple iOS and macOS=10.5.2
Apple Mac OS X Server=10.4.11
Apple Mac OS X Server=10.5.2
Microsoft Windows Vista
Microsoft Windows XP
Apple Safari=3
Apple Safari=3.1
Remediation
Patch Available
Patch Available
Event History
Apr 17, 2008
CVE Published
via MITRE·05:00 PM
Data Sourced
via MITRE·05:00 PM
Description
Data Sourced
07:05 PM
DescriptionWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2008-1026?
CVE-2008-1026 is considered a critical vulnerability due to its potential for remote code execution.
2
How do I fix CVE-2008-1026?
To fix CVE-2008-1026, users should update Safari to version 3.1.1 or later.
3
Which versions of Safari are affected by CVE-2008-1026?
CVE-2008-1026 affects Safari versions before 3.1.1.
4
Can CVE-2008-1026 be exploited remotely?
Yes, CVE-2008-1026 can be exploited remotely via specially crafted regular expressions.
5
What types of systems are impacted by CVE-2008-1026?
CVE-2008-1026 impacts systems running Safari before version 3.1.1 on macOS and Windows.