CVE-2007-1661

Advisory lineage Upstream: 0 Downstream: 4
Modified
Published: 07 Nov 2007, 20:00
Last modified:07 Aug 2024, 13:06

Vulnerability Summary

Overall Risk (default)
medium
26/100
CVSS Score
6.4 MEDIUM
v2.0 (nvd)
EPSS Score
2.03% LOW
2% probability -0.68%
KEV
Not listed
Ransomware
No reports
Public exploits
None found
Dark Web
Not detected

Timeline

07 Nov 2007, 20:00
Published
Vulnerability first disclosed
07 Aug 2024, 13:06
Last Modified
Vulnerability information updated

Description

Perl-Compatible Regular Expression (PCRE) library before 7.3 backtracks too far when matching certain input bytes against some regex patterns in non-UTF-8 mode, which allows context-dependent attackers to obtain sensitive information or cause a denial of service (crash), as demonstrated by the "\X?\d" and "\P{L}?\d" patterns.

CVSS Metrics

  • v2.0MEDIUMScore: 6.4AV:N/AC:L/Au:N/C:P/I:N/A:P

EPSS Trends

Current EPSS score: 2.03% Percentile: 84%

Affected Systems

  • applemac_os_x

    10.4.11

  • applemac_os_x_server

    10.4.11

  • pcreperl-compatible_regular_expression_library

    ≤ 7.2 | 7.0 | 7.1

References (44)