CVE-2017-8399
Severity CVSS v4.0:
Pending analysis
Type:
CWE-119
Buffer Errors
Publication date:
01/05/2017
Last modified:
20/04/2025
Description
PCRE2 before 10.30 has an out-of-bounds write caused by a stack-based buffer overflow in pcre2_match.c, related to a "pattern with very many captures."
Impact
Base Score 3.x
9.80
Severity 3.x
CRITICAL
Base Score 2.0
7.50
Severity 2.0
HIGH
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:a:pcre:pcre2:*:*:*:*:*:*:*:* | 10.30 (excluding) |
To consult the complete list of CPE names with products and versions, see this page
References to Advisories, Solutions, and Tools
- http://www.securityfocus.com/bid/98315
- https://bugs.chromium.org/p/oss-fuzz/issues/detail?id=783
- https://security.gentoo.org/glsa/201710-09
- https://vcs.pcre.org/pcre2/code/tags/pcre2-10.30/ChangeLog?revision=854&view=markup
- https://vcs.pcre.org/pcre2?view=revision&revision=674
- http://www.securityfocus.com/bid/98315
- https://bugs.chromium.org/p/oss-fuzz/issues/detail?id=783
- https://security.gentoo.org/glsa/201710-09
- https://vcs.pcre.org/pcre2/code/tags/pcre2-10.30/ChangeLog?revision=854&view=markup
- https://vcs.pcre.org/pcre2?view=revision&revision=674



