First published: Tue Jul 11 2017(Updated: )
In PCRE 8.41, the OP_KETRMAX feature in the match function in pcre_exec.c allows stack exhaustion (uncontrolled recursion) when processing a crafted regular expression.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
PCRE | =8.41 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2017-11164 is classified as a high severity vulnerability due to the potential for stack exhaustion.
To mitigate CVE-2017-11164, update PCRE to a version later than 8.41 that does not contain this vulnerability.
CVE-2017-11164 affects PCRE version 8.41, which is a Perl Compatible Regular Expressions library.
CVE-2017-11164 enables attackers to cause stack exhaustion through crafted regular expressions.
CVE-2017-11164 was disclosed on July 11, 2017.