CVE-2007-1661
Published Nov 7, 2007
Last updated 6 years ago
Overview
- Description
- Perl-Compatible Regular Expression (PCRE) library before 7.3 backtracks too far when matching certain input bytes against some regex patterns in non-UTF-8 mode, which allows context-dependent attackers to obtain sensitive information or cause a denial of service (crash), as demonstrated by the "\X?\d" and "\P{L}?\d" patterns.
- Source
- cve@mitre.org
- NVD status
- Modified
Risk scores
CVSS 2.0
- Type
- Primary
- Base score
- 6.4
- Impact score
- 4.9
- Exploitability score
- 10
- Vector string
- AV:N/AC:L/Au:N/C:P/I:N/A:P
Weaknesses
- nvd@nist.gov
- NVD-CWE-Other
Social media
- Hype score
- Not currently trending
Configurations
[ { "nodes": [ { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:a:pcre:perl-compatible_regular_expression_library:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "346F4175-3DD5-4EA5-A10D-F062C7D93A15", "versionEndIncluding": "7.2" }, { "criteria": "cpe:2.3:a:pcre:perl-compatible_regular_expression_library:7.0:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "4E211904-BCCB-4408-8027-CE4C81B6C6C8" }, { "criteria": "cpe:2.3:a:pcre:perl-compatible_regular_expression_library:7.1:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "79B62828-588E-4279-BB0D-96247B97041E" } ], "operator": "OR" } ] }, { "nodes": [ { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:o:apple:mac_os_x:10.4.11:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "6EE39585-CF3B-4493-96D8-B394544C7643" }, { "criteria": "cpe:2.3:o:apple:mac_os_x_server:10.4.11:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "D09D5933-A7D9-4A61-B863-CD8E7D5E67D8" } ], "operator": "OR" } ] } ]