PatchSiren

Pcre CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

HIGH Pcre CVE published 2017-02-16

CVE-2017-6004

CVE-2017-6004 is a denial-of-service issue in PCRE’s JIT compilation path. According to NVD, the flaw can be triggered by a crafted regular expression and may cause an out-of-bounds read followed by an application crash. NVD rates the issue as high severity (CVSS 3.0: 7.5) with network attack vector and no privileges or user interaction required. The record links the fix to an upstream PCRE patch (revisio [truncated]