suse · CVE-2015-8380

Quick triage

Priority: high Published: 2021-05-30 13:35:06 UTC Updated: 2026-04-18 18:09:03 UTC

View at Official suse advisory, NVD, CVE.org · CVE detail

Freshness: upstream tracker timestamp is available; use API updated time as primary recency signal.

Tracker summary

CVE-2015-8380 severity important: SUSE including 42 source package names (0.9.1:libpcre1-8.39-7.1, 1.0.0:libpcre1-8.39-7.1, …), 258 product×package rows across 94 product lines (Container caasp/v4/default-http-backend, Container caasp/v4/dnsmasq-nanny, … (94 product lines)): Fixed 145, Known Not Affected 113.

Description:

The pcre_exec function in pcre_exec.c in PCRE before 8.38 mishandles a // pattern with a \01 string, which allows remote attackers to cause a denial of service (heap-based buffer overflow) or possibly have unspecified other impact via a crafted regular expression, as demonstrated by a JavaScript RegExp object encountered by Konqueror.

cvelogic Threat Intelligence