CVE-2008-2371: Buffer Overflow
Heap-based buffer overflow in pcrecompile.c in the Perl-Compatible Regular Expression (PCRE) library 7.7 allows context-dependent attackers to cause a denial of service (crash) or possibly execute arbitrary code via a regular expression that begins with an option and contains multiple branches.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2008-2371?
CVE-2008-2371 has a high severity rating due to the potential for an attacker to execute arbitrary code or cause a denial of service by exploiting the flaw.
How do I fix CVE-2008-2371?
To fix CVE-2008-2371, update to the latest version of the PCRE library or apply recommended patches provided by your software vendor.
What software is affected by CVE-2008-2371?
CVE-2008-2371 affects PCRE version 7.7, as well as certain versions of PHP and various Linux distributions including Debian and Ubuntu.
What are the consequences of exploiting CVE-2008-2371?
Exploiting CVE-2008-2371 can lead to application crashes or potentially allow attackers to execute arbitrary code on the affected systems.
Is CVE-2008-2371 exploitable remotely?
Yes, CVE-2008-2371 can be exploited remotely through malicious regular expressions crafted by an attacker.