CVE-2006-7226

Advisory lineage Upstream: 0 Downstream: 3
Modified
Published: 03 Dec 2007, 20:00
Last modified:07 Aug 2024, 20:57

Vulnerability Summary

Overall Risk (default)
low
18/100
CVSS Score
4.3 MEDIUM
v2.0 (nvd)
EPSS Score
1.72% LOW
2% probability -0.02%
KEV
Not listed
Ransomware
No reports
Public exploits
None found
Dark Web
Not detected

Timeline

03 Dec 2007, 20:00
Published
Vulnerability first disclosed
07 Aug 2024, 20:57
Last Modified
Vulnerability information updated

Description

Perl-Compatible Regular Expression (PCRE) library before 6.7 does not properly calculate the compiled memory allocation for regular expressions that involve a quantified "subpattern containing a named recursion or subroutine reference," which allows context-dependent attackers to cause a denial of service (error or crash).

CVSS Metrics

  • v2.0MEDIUMScore: 4.3AV:N/AC:M/Au:N/C:N/I:N/A:P

EPSS Trends

Current EPSS score: 1.72% Percentile: 83%

Affected Systems

  • redhatenterprise_linux

    4.0

  • redhatenterprise_linux_desktop

    4.0

References (12)