#VU39076 Heap-based buffer overflow in PCRE2 - CVE-2017-8786 

 

#VU39076 Heap-based buffer overflow in PCRE2 - CVE-2017-8786

Published: May 5, 2017 / Updated: December 5, 2020


Vulnerability identifier: #VU39076
Vulnerability risk: High
CVSSv4.0: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/U:Amber
CVE-ID: CVE-2017-8786
CWE-ID: CWE-122
Exploitation vector: Remote access
Exploit availability: No public exploit available
Vulnerable software:
PCRE2
Software vendor:
PCRE

Description

The vulnerability allows a remote attacker to execute arbitrary code on the target system.

The vulnerability exists due to a boundary error in pcre2test.c in PCRE2 10.23. A remote attacker can use a crafted regular expression. to trigger heap-based buffer overflow and execute arbitrary code on the target system.

Successful exploitation of this vulnerability may result in complete compromise of vulnerable system.


Remediation

Install update from vendor's website.

External links