CVE-2017-16231

Name
CVE-2017-16231
Description
In PCRE 8.41, after compiling, a pcretest load test PoC produces a crash overflow in the function match() in pcre_exec.c because of a self-recursive call. NOTE: third parties dispute the relevance of this report, noting that there are options that can be used to limit the amount of stack that is used
NVD Severity
medium
Other trackers
Mailing lists
Exploits
Forges
GitHub (code, issues), Aports (code, issues)

References

Type URI
MISC http://packetstormsecurity.com/files/150897/PCRE-8.41-Buffer-Overflow.html
MISC http://seclists.org/fulldisclosure/2018/Dec/33
MISC http://www.openwall.com/lists/oss-security/2017/11/01/11
MISC http://www.openwall.com/lists/oss-security/2017/11/01/3
MISC http://www.openwall.com/lists/oss-security/2017/11/01/7
MISC http://www.openwall.com/lists/oss-security/2017/11/01/8
MISC http://www.securityfocus.com/bid/101688
CONFIRM https://bugs.exim.org/show_bug.cgi?id=2047

Match rules

CPE URI Source package Min version Max version
n/a == n/a == n/a

Vulnerable and fixed packages

Source package Branch Version Maintainer Status