suse · CVE-2015-5073

Quick triage

Priority: critical Published: 2021-05-30 13:31:30 UTC Updated: 2026-04-18 18:15:58 UTC

View at Official suse advisory, NVD, CVE.org · CVE detail

Freshness: upstream tracker timestamp is available; use API updated time as primary recency signal.

Tracker summary

CVE-2015-5073 severity critical: SUSE including 40 source package names (0.9.1:libpcre1-8.39-7.1, 1.0.0:libpcre1-8.39-7.1, …), 178 product×package rows across 74 product lines (Container caasp/v4/default-http-backend, Container caasp/v4/dnsmasq-nanny, … (74 product lines)): Fixed 149, Known Not Affected 29.

Description:

Heap-based buffer overflow in the find_fixedlength function in pcre_compile.c in PCRE before 8.38 allows remote attackers to cause a denial of service (crash) or obtain sensitive information from heap memory and possibly bypass the ASLR protection mechanism via a crafted regular expression with an excess closing parenthesis.

cvelogic Threat Intelligence