CVE-2020-14155
בינונית 5.3
תיאור (מקור, אנגלית)
libpcre in PCRE before 8.44 allows an integer overflow via a large number after a (?C substring.
מדדים
- CVSS 3.1
-
5.3 (MEDIUM)
מקור הציון: NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L - CWE
- CWE-190
מוצרים מושפעים
pcre: pcre; apple: macos; gitlab: gitlab; oracle: communications cloud native core policy; netapp: active iq unified manager; netapp: cloud backup; netapp: clustered data ontap; netapp: ontap select deploy administration utility; netapp: steelstore cloud integrated storage; netapp: h410c firmware; netapp: h410c; netapp: h300s firmware; netapp: h300s; netapp: h500s firmware; netapp: h500s
קישורים
- https://www.pcre.org/original/changelog.txt Release NotesVendor Advisory
- https://www.pcre.org/original/changelog.txt Release NotesVendor Advisory
- https://bugs.gentoo.org/717920 Issue TrackingPatchThird Party Advisory
- https://www.oracle.com/security-alerts/cpuapr2022.html PatchThird Party Advisory
- https://bugs.gentoo.org/717920 Issue TrackingPatchThird Party Advisory
- https://www.oracle.com/security-alerts/cpuapr2022.html PatchThird Party Advisory
- http://seclists.org/fulldisclosure/2020/Dec/32 Mailing ListThird Party Advisory
- http://seclists.org/fulldisclosure/2021/Feb/14 Mailing ListThird Party Advisory
- https://about.gitlab.com/releases/2020/07/01/security-release-13-1-2-release/ Third Party Advisory
- https://lists.apache.org/thread.html/rf9fa47ab66495c78bb4120b0754dd9531ca2ff04… Mailing ListThird Party Advisory