It was reported that pcreexec in PHP pcre extension partially initialize a buffer when an invalid regex is processed, which can information disclosure.
A mitigation fix have been applied in PHP 5.4+ http://git.php.net/?p=php-src.git;a=commitdiff;h=c351b47ce85a3a147cfa801fa9f0149ab4160834
Upstream bug report (with a patch proposal): http://bugs.exim.org/showbug.cgi?id=1537