debian · CVE-2007-1661

Quick triage

Priority: unimportant Published: Updated: Sun, 28 Jun 2026 03:01:32 GMT

View at Official debian advisory, NVD, CVE.org · CVE detail

Freshness: upstream tracker timestamp is available; use API updated time as primary recency signal.

Tracker summary

CVE-2007-1661 unimportant priority: Debian including 2 source packages (glib2.0, pcre3), 7 status rows across 5 suites (bookworm, bullseye, forky, sid, trixie): resolved 7.

Description:

Perl-Compatible Regular Expression (PCRE) library before 7.3 backtracks too far when matching certain input bytes against some regex patterns in non-UTF-8 mode, which allows context-dependent attackers to obtain sensitive information or cause a denial of service (crash), as demonstrated by the "\X?\d" and "\P{L}?\d" patterns.

cvelogic Threat Intelligence