« List of all CVEs

CVE-2014-9769

Published: 3/28/2016 Last updated: 8/6/2024 Reserved: 3/28/2016

pcre_jit_compile.c in PCRE 8.35 does not properly use table jumps to optimize nested alternatives, which allows remote attackers to cause a denial of service (stack memory corruption) or possibly have unspecified other impact via a crafted string, as demonstrated by packets encountered by Suricata during use of a regular expression in an Emerging Threats Open ruleset.

CNA assigner: debian (79363d38-fa19-49d1-9214-5f28da3f3ac5) Requested by: n/a

Opam packages affected (6)

conf-libpcre conf-libpcre2-8 conf-mingw-w64-pcre2-i686 conf-mingw-w64-pcre2-x86_64 conf-mingw-w64-pcre-i686 conf-mingw-w64-pcre-x86_64

Products affected (1)

Product Vendor Version
n/a n/a < e208668ef7ba23efcbf76a8200cab8deee501c4d

References (12)