CVE-2015-2328: High severity oracle linux vulnerability
PCRE before 8.36 mishandles the /((?(R)a|(?1)))+/ pattern and related patterns with certain recursion, which allows remote attackers to cause a denial of service (segmentation fault) or possibly have unspecified other impact via a crafted regular expression, as demonstrated by a JavaScript RegExp object encountered by Konqueror.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2015-2328?
CVE-2015-2328 has a high severity level due to its potential to cause denial of service through crafted regular expressions.
How do I fix CVE-2015-2328?
To fix CVE-2015-2328, upgrade to PCRE version 8.36 or higher.
What software is affected by CVE-2015-2328?
CVE-2015-2328 affects PCRE versions up to 8.35 and Oracle Linux 7.
What impact does CVE-2015-2328 have?
CVE-2015-2328 can lead to segmentation faults or potentially other unspecified impacts when triggered.
Is CVE-2015-2328 a code injection vulnerability?
No, CVE-2015-2328 is not a code injection vulnerability but rather a denial of service issue related to regular expressions.