Heap-based buffer overflow in PCRE and PCRE2 - CVE-2015-8381

 

Heap-based buffer overflow in PCRE and PCRE2 - CVE-2015-8381

Published: July 20, 2022


Vulnerability identifier: #VU65555
CSH Severity: High
CVSS v4: 9.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2015-8381
CWE-ID: CWE-122
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to execute arbitrary code on the target system.

The vulnerability exists due to a boundary error in the compile_regex() function in pcre_compile.c in PCRE when handling related patterns with certain group references. A remote attacker can use a crafted regular expression to trigger a heap-based buffer overflow and execute arbitrary code on the target system.

Successful exploitation of this vulnerability may result in complete compromise of vulnerable system.


Affected software

PCRE
PCRE2
IBM Operations Analytics Predictive Insights
IBM Security Guardium Key Lifecycle Manager (GKLM)
IBM Intelligent Operations Center
WebSphere Remote Server
IBM Security Verify Governance
IBM Tivoli Business Service Manager
IBM Cloud Application Performance Management (APM)
Db2 Big SQL
IBM OpenPages with Watson
dashDB Local
Storage Protect Server
IBM Cloud Pak System
IBM DB2 LUW

How to mitigate CVE-2015-8381

Install update from vendor's website.

PCRE - update to 8.38
PCRE2 - update to 10.20
Db2 Big SQL - update to 7.6.2
dashDB Local - update to 11.5.9.0
IBM Cloud Pak System - addressed in versions 2.3.4.1, 2.3.5.0
IBM Tivoli Business Service Manager - update to 6.2.0.5.4
IBM Cloud Application Performance Management (APM) - update to 8.1.4.0.15
Storage Protect Server - update to 8.1.22
IBM DB2 LUW - addressed in versions 10.5 FP11, 11.1.4 FP7, 11.5.0, 11.5.8

External References

Related Security Bulletins