CVE-2005-2491
Summary
| CVE | CVE-2005-2491 |
|---|---|
| State | PUBLISHED |
| Assigner | redhat |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2005-08-23 04:00:00 UTC |
| Updated | 2025-04-03 01:03:51 UTC |
| Description | Integer overflow in pcre_compile.c in Perl Compatible Regular Expressions (PCRE) before 6.2, as used in multiple products such as Python, Ethereal, and PHP, allows attackers to execute arbitrary code via quantifier values in regular expressions, which leads to a heap-based buffer overflow. |
Risk And Classification
Primary CVSS: v2.0 7.5 from [email protected]
AV:N/AC:L/Au:N/C:P/I:P/A:P
Problem Types: NVD-CWE-Other | n/a
CVSS v2.0 Breakdown
Access Vector
NetworkAccess Complexity
LowAuthentication
NoneConfidentiality
PartialIntegrity
PartialAvailability
PartialAV:N/AC:L/Au:N/C:P/I:P/A:P
NVD Known Affected Configurations (CPE 2.3)
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Secunia - Advisories - Mac OS X Security Update Fixes Multiple Vulnerabilities | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | |
| Security Announcement | af854a3a-2127-422b-91ae-364da2661108 | www.novell.com | |
| ftp.sco.com/pub/updates/OpenServer/SCOSA-2006.10/SCOSA-2006.10.txt | af854a3a-2127-422b-91ae-364da2661108 | ftp.sco.com | |
| Repository / Oval Repository | af854a3a-2127-422b-91ae-364da2661108 | oval.cisecurity.org | |
| Repository / Oval Repository | af854a3a-2127-422b-91ae-364da2661108 | oval.cisecurity.org | |
| Webmail - OVH | af854a3a-2127-422b-91ae-364da2661108 | www.vupen.com | |
| Gentoo Linux Documentation -- Apache, mod_ssl: Multiple vulnerabilities | af854a3a-2127-422b-91ae-364da2661108 | www.gentoo.org | |
| SecurityFocus | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | |
| SecurityReason | af854a3a-2127-422b-91ae-364da2661108 | securityreason.com | |
| Pony Mail! | af854a3a-2127-422b-91ae-364da2661108 | lists.apache.org | |
| Pony Mail! | af854a3a-2127-422b-91ae-364da2661108 | lists.apache.org | |
| PHP: PHP 4.4.1 Release Announcement | af854a3a-2127-422b-91ae-364da2661108 | www.php.net | |
| Debian -- Security Information -- DSA-821-1 python2.3 | af854a3a-2127-422b-91ae-364da2661108 | www.debian.org | |
| Pony Mail! | af854a3a-2127-422b-91ae-364da2661108 | lists.apache.org | |
| '[security bulletin] HPSBOV02683 SSRT090208 rev.1 - HP Secure Web Server (SWS) for OpenVMS running Ap' - MARC | af854a3a-2127-422b-91ae-364da2661108 | marc.info | |
| Debian -- Security Information -- DSA-817-1 python2.2 | af854a3a-2127-422b-91ae-364da2661108 | www.debian.org | |
| VMware ESX Server Multiple Vulnerabilities - Advisories - Secunia | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | |
| Pony Mail! | af854a3a-2127-422b-91ae-364da2661108 | lists.apache.org | |
| Webmail - OVH | af854a3a-2127-422b-91ae-364da2661108 | www.vupen.com | |
| SecurityTracker.com Archives - PCRE Heap Overflow May Let Users Execute Arbitrary Code | af854a3a-2127-422b-91ae-364da2661108 | securitytracker.com | Patch |
| Repository / Oval Repository | af854a3a-2127-422b-91ae-364da2661108 | oval.cisecurity.org | |
| About Security Update 2005-009 | af854a3a-2127-422b-91ae-364da2661108 | docs.info.apple.com | |
| Avaya Products Integer Overflow and Denial of Service - Secunia Advisories - Vulnerability Intelligence - Secunia.com | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | |
| SGI Advanced Linux Environment Multiple Updates - Advisories - Secunia | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | |
| HP System Management Homepage PHP Multiple Vulnerabilities - Advisories - Secunia | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | |
| Gentoo Linux Documentation -- Gnumeric: Heap overflow in the included PCRE library | af854a3a-2127-422b-91ae-364da2661108 | www.gentoo.org | |
| patches.sgi.com/support/free/security/advisories/20060401-01-U | af854a3a-2127-422b-91ae-364da2661108 | patches.sgi.com | |
| Pony Mail! | af854a3a-2127-422b-91ae-364da2661108 | lists.apache.org | |
| #102198: Security Vulnerabilities in the Apache 2 Web Server | af854a3a-2127-422b-91ae-364da2661108 | sunsolve.sun.com | |
| ASA-2006-159 (RHSA-2006-0197) | af854a3a-2127-422b-91ae-364da2661108 | support.avaya.com | |
| Gentoo Linux Documentation -- libpcre: Heap integer overflow | af854a3a-2127-422b-91ae-364da2661108 | www.gentoo.org | |
| rhn.redhat.com | Red Hat Support | af854a3a-2127-422b-91ae-364da2661108 | www.redhat.com | |
| Secunia - Advisories - PCRE Quantifier Values Integer Overflow Vulnerability | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | |
| Pony Mail! | af854a3a-2127-422b-91ae-364da2661108 | lists.apache.org | |
| 1. Overview: | af854a3a-2127-422b-91ae-364da2661108 | support.avaya.com | |
| Webmail : Solution de messagerie professionnelle - OVHcloud- OVH | af854a3a-2127-422b-91ae-364da2661108 | www.vupen.com | |
| Pony Mail! | af854a3a-2127-422b-91ae-364da2661108 | lists.apache.org | |
| support.avaya.com/elmodocs2/security/ASA-2005-216.pdf | af854a3a-2127-422b-91ae-364da2661108 | support.avaya.com | |
| TSLSA-2005-0059 - multi | af854a3a-2127-422b-91ae-364da2661108 | lists.trustix.org | |
| rhn.redhat.com | Red Hat Support | af854a3a-2127-422b-91ae-364da2661108 | www.redhat.com | |
| Debian -- Security Information -- DSA-800-1 pcre3 | af854a3a-2127-422b-91ae-364da2661108 | www.debian.org | |
| 'SUSE Security Announcement: php4, php5 remote code execution' - MARC | af854a3a-2127-422b-91ae-364da2661108 | marc.info | |
| Ethereal: enpa-sa-00021 | af854a3a-2127-422b-91ae-364da2661108 | www.ethereal.com | URL Repurposed |
| Secunia - Advisories - Sun Solaris Multiple Apache2 Vulnerabilities | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | |
| Pony Mail! | af854a3a-2127-422b-91ae-364da2661108 | lists.apache.org | |
| SecurityFocus | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | |
| Webmail - OVH | af854a3a-2127-422b-91ae-364da2661108 | www.vupen.com | |
| Pony Mail! | af854a3a-2127-422b-91ae-364da2661108 | lists.apache.org | |
| IT Resource Center - login / register | af854a3a-2127-422b-91ae-364da2661108 | itrc.hp.com | |
| Pony Mail! | af854a3a-2127-422b-91ae-364da2661108 | lists.apache.org | |
| Pony Mail! | af854a3a-2127-422b-91ae-364da2661108 | lists.apache.org | |
| Support | af854a3a-2127-422b-91ae-364da2661108 | www.redhat.com | |
| Repository / Oval Repository | af854a3a-2127-422b-91ae-364da2661108 | oval.cisecurity.org | |
| Secunia - Advisories - Avaya Intuity LX Two Vulnerabilities | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | |
| Webmail : Solution de messagerie professionnelle - OVHcloud- OVH | af854a3a-2127-422b-91ae-364da2661108 | www.vupen.com | |
| Secunia - Advisories - Debian update for pcre3 | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | |
| RETIRED: Apple Mac OS X Security Update 2005-009 Multiple Vulnerabilities | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | |
| Secunia - Advisories - SCO OpenServer Updates for Multiple Packages | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | |
| Gentoo Linux Documentation -- PHP: Vulnerabilities in included PCRE and XML-RPC libraries | af854a3a-2127-422b-91ae-364da2661108 | www.gentoo.org | |
| Security Announcement | af854a3a-2127-422b-91ae-364da2661108 | www.novell.com | |
| '[OpenPKG-SA-2005.018] OpenPKG Security Advisory (pcre)' - MARC | af854a3a-2127-422b-91ae-364da2661108 | marc.info | |
| support.avaya.com/elmodocs2/security/ASA-2005-223.pdf | af854a3a-2127-422b-91ae-364da2661108 | support.avaya.com | |
| Gentoo Linux Documentation -- Python: Heap overflow in the included PCRE library | af854a3a-2127-422b-91ae-364da2661108 | www.gentoo.org | |
| Debian -- Security Information -- DSA-819-1 python2.1 | af854a3a-2127-422b-91ae-364da2661108 | www.debian.org | |
| Pony Mail! | af854a3a-2127-422b-91ae-364da2661108 | lists.apache.org | |
| PCRE Regular Expression Heap Overflow Vulnerability | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | |
| Security Announcement | af854a3a-2127-422b-91ae-364da2661108 | www.novell.com | |
| Pony Mail! | MITRE | lists.apache.org | |
| Pony Mail! | MITRE | lists.apache.org | |
| Pony Mail! | MITRE | lists.apache.org | |
| Pony Mail! | MITRE | lists.apache.org | |
| Pony Mail! | MITRE | lists.apache.org | |
| Pony Mail! | MITRE | lists.apache.org | |
| Pony Mail! | MITRE | lists.apache.org | |
| Pony Mail! | MITRE | lists.apache.org | |
| Pony Mail! | MITRE | lists.apache.org | |
| Pony Mail! | MITRE | lists.apache.org | |
| Pony Mail! | MITRE | lists.apache.org | |
| Pony Mail! | MITRE | lists.apache.org | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
Vendor Comments And Credit
| Organization | Published | Contributor | Statement |
|---|---|---|---|
| Apache | 2008-07-02 | Mark J Cox | Fixed in Apache 2.0.55: http://httpd.apache.org/security/vulnerabilities_20.html |
There are currently no legacy QID mappings associated with this CVE.