Use of uninitialized resource in PCRE - CVE-2015-8390

 

Use of uninitialized resource in PCRE - CVE-2015-8390

Published: June 20, 2023


Vulnerability identifier: #VU77578
CSH Severity: Medium
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2015-8390
CWE-ID: CWE-908
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to bypass certain security restrictions.

The vulnerability exists due to usage of uninitialized resources when processing the [: and \ substrings in character classes. A remote attacker can pass specially crafted data to the application, trigger uninitialized usage of resources and bypass implemented security mechanisms.


Affected software

PCRE
Amazon Linux AMI
Fedora
IBM Operations Analytics Predictive Insights
IBM Security Guardium Key Lifecycle Manager (GKLM)
IBM Intelligent Operations Center
WebSphere Remote Server
IBM Security Verify Governance
IBM Tivoli Business Service Manager
IBM Cloud Application Performance Management (APM)
Db2 Big SQL
IBM OpenPages with Watson
dashDB Local
Storage Protect Server
IBM Cloud Pak System
glib2
pcre
IBM DB2 LUW

How to mitigate CVE-2015-8390

Install updates from vendor's website.

PCRE - update to 8.38
Db2 Big SQL - update to 7.6.2
dashDB Local - update to 11.5.9.0
IBM Cloud Pak System - addressed in versions 2.3.4.1, 2.3.5.0
glib2 - update to 2.36.3-5.26
IBM Tivoli Business Service Manager - update to 6.2.0.5.4
IBM Cloud Application Performance Management (APM) - update to 8.1.4.0.15
Storage Protect Server - update to 8.1.22
pcre - update to 8.21-7.9
pcre - update to 8.38-1.fc22
IBM DB2 LUW - addressed in versions 10.5 FP11, 11.1.4 FP7, 11.5.0, 11.5.8

External References

Related Security Bulletins