PCRE Perl Compatible Regular Expressions Library POSIX Denial Of Service Vulnerability
BID:26725
Info
PCRE Perl Compatible Regular Expressions Library POSIX Denial Of Service Vulnerability
| Bugtraq ID: | 26725 |
| Class: | Access Validation Error |
| CVE: |
CVE-2006-7225 |
| Remote: | Yes |
| Local: | No |
| Published: | Jul 04 2006 12:00AM |
| Updated: | Feb 01 2008 05:07PM |
| Credit: | Ludwig Nussel reported this issue. |
| Vulnerable: |
SuSE SUSE Linux Enterprise SDK 9 SuSE SUSE Linux Enterprise SDK 10.SP1 SuSE Suse Linux Enterprise Desktop 10 SP1 SuSE Linux 10.1 x86-64 SuSE Linux 10.1 x86 SuSE Linux 10.1 ppc S.u.S.E. openSUSE 10.3 S.u.S.E. openSUSE 10.2 S.u.S.E. Open-Enterprise-Server 0 S.u.S.E. Novell Linux POS 9 S.u.S.E. Novell Linux Desktop SDK 9.0 PCRE PCRE 6.2 PCRE PCRE 6.1 PCRE PCRE 6.0 PCRE PCRE 5.0 PCRE PCRE 4.5 PCRE PCRE 4.4 PCRE PCRE 3.9 PCRE PCRE 3.7 PCRE PCRE 3.4 MandrakeSoft Multi Network Firewall 2.0 MandrakeSoft Corporate Server 3.0 x86_64 MandrakeSoft Corporate Server 3.0 Avaya SES 3.1.2 Avaya SES 3.1.1 Avaya SES 4.0 Avaya Messaging Storage Server MSS 3.0 Avaya Messaging Storage Server MM3.0 Avaya Messaging Storage Server 3.1 Avaya Message Networking MN 3.1 Avaya Message Networking 3.1 Avaya Intuity AUDIX LX 2.0 Avaya Communication Manager 4.0 Avaya Communication Manager 3.1 Avaya Communication Manager 3.0 Avaya CCS 3.1.2 Avaya CCS 3.1.1 Avaya CCS 4.0 Avaya Aura Application Enablement Services 4.0.1 Avaya AES 4.0 |
| Not Vulnerable: |
PCRE PCRE 7.4 PCRE PCRE 6.7 |
Discussion
PCRE Perl Compatible Regular Expressions Library POSIX Denial Of Service Vulnerability
PCRE (Perl Compatible Regular Expressions) is prone to a denial-of-service vulnerability because it fails to adequately sanitize user-supplied regular expressions.
A successful attack will cause an application using the library to crash, denying service to legitimate users.
Versions prior to PCRE 6.7 are vulnerable.
PCRE (Perl Compatible Regular Expressions) is prone to a denial-of-service vulnerability because it fails to adequately sanitize user-supplied regular expressions.
A successful attack will cause an application using the library to crash, denying service to legitimate users.
Versions prior to PCRE 6.7 are vulnerable.
Exploit / POC
PCRE Perl Compatible Regular Expressions Library POSIX Denial Of Service Vulnerability
Attackers can exploit this issue via a browser.
Attackers can exploit this issue via a browser.
Solution / Fix
PCRE Perl Compatible Regular Expressions Library POSIX Denial Of Service Vulnerability
Solution:
The vendor released PCRE 6.7 to address this issue. Please see the references for more information.
PCRE PCRE 3.4
PCRE PCRE 3.7
PCRE PCRE 3.9
PCRE PCRE 4.4
PCRE PCRE 4.5
PCRE PCRE 5.0
PCRE PCRE 6.0
PCRE PCRE 6.1
PCRE PCRE 6.2
Solution:
The vendor released PCRE 6.7 to address this issue. Please see the references for more information.
PCRE PCRE 3.4
-
PCRE pcre-7.4.tar.gz
ftp://ftp.csx.cam.ac.uk/pub/software/programming/pcre/pcre-7.4.tar.gz
PCRE PCRE 3.7
-
PCRE pcre-7.4.tar.gz
ftp://ftp.csx.cam.ac.uk/pub/software/programming/pcre/pcre-7.4.tar.gz
PCRE PCRE 3.9
-
PCRE pcre-7.4.tar.gz
ftp://ftp.csx.cam.ac.uk/pub/software/programming/pcre/pcre-7.4.tar.gz
PCRE PCRE 4.4
-
PCRE pcre-7.4.tar.gz
ftp://ftp.csx.cam.ac.uk/pub/software/programming/pcre/pcre-7.4.tar.gz
PCRE PCRE 4.5
-
PCRE pcre-7.4.tar.gz
ftp://ftp.csx.cam.ac.uk/pub/software/programming/pcre/pcre-7.4.tar.gz
PCRE PCRE 5.0
-
PCRE pcre-7.4.tar.gz
ftp://ftp.csx.cam.ac.uk/pub/software/programming/pcre/pcre-7.4.tar.gz
PCRE PCRE 6.0
-
PCRE pcre-7.4.tar.gz
ftp://ftp.csx.cam.ac.uk/pub/software/programming/pcre/pcre-7.4.tar.gz
PCRE PCRE 6.1
-
PCRE pcre-7.4.tar.gz
ftp://ftp.csx.cam.ac.uk/pub/software/programming/pcre/pcre-7.4.tar.gz
PCRE PCRE 6.2
-
PCRE pcre-7.4.tar.gz
ftp://ftp.csx.cam.ac.uk/pub/software/programming/pcre/pcre-7.4.tar.gz
References
PCRE Perl Compatible Regular Expressions Library POSIX Denial Of Service Vulnerability
References:
References:
- PCRE Homepage (PCRE)
- PCRE Regular Expression Library Changelog (PCRE)
- [security-announce] SUSE Security Announcement: php4, php5 (SUSE-SA:2008:004) (SUSE)
- ASA-2007-505 PCRE security update (RHSA-2007-1068) (Avaya)
- RHSA-2007:1059-9 - Important: pcre security update (Red Hat)
- RHSA-2007:1068-3: pcre security update (Red Hat)
- SUSE Security Advisory SUSE-SA:2008:004 (SUSE)