CVE-2008-2371
Publication date 7 July 2008
Last updated 24 July 2024
Ubuntu priority
Heap-based buffer overflow in pcre_compile.c in the Perl-Compatible Regular Expression (PCRE) library 7.7 allows context-dependent attackers to cause a denial of service (crash) or possibly execute arbitrary code via a regular expression that begins with an option and contains multiple branches.
Status
Package | Ubuntu Release | Status |
---|---|---|
erlang | ||
pcre3 | ||
php5 | ||
Notes
jdstrand
kees did pcre3 update php5 on dapper and feisty is not vulnerable jdstrand sponsored erlang update for karmic and lucid
Patch details
Package | Patch details |
---|---|
erlang |
|
php5 |