Secunia Logo  


Secunia PSI WorldMap
 
CVE Reference: CVE-2006-7226
NOTE: The text on this page is written by CVE MITRE and reflects neither the opinions of Secunia or the results of our research. All data on this page is written and maintained by CVE MITRE.

Original Page at CVE MITRE:
CVE-2006-7226

Description:
Perl-Compatible Regular Expression (PCRE) library before 6.7 does not properly calculate the compiled memory allocation for regular expressions that involve a quantified "subpattern containing a named recursion or subroutine reference," which allows context-dependent attackers to cause a denial of service (error or crash).

CVE Status:
Candidate

References:

XF
  http://xforce.iss.net/xforce/xfdb/40020

SUSE
  http://lists.opensuse.org/opensuse-security-announce/2008-01/msg00006.html

SAID
  Secunia Advisory: SA28041
  Secunia Advisory: SA28658

REDHAT
  http://www.redhat.com/support/errata/RHSA-2007-1059.html
  http://www.redhat.com/support/errata/RHSA-2007-1068.html

MISC

MANDRIVA
  http://www.mandriva.com/security/advisories?name=MDVSA-2008:030

CONFIRM
  http://www.pcre.org/changelog.txt
  http://support.avaya.com/elmodocs2/security/ASA-2007-505.htm

BID
  26727


Return to the previous page.