CVE-2006-7230

Impact:
Important
Public Date:
2007-11-20
Bugzilla:
384801: CVE-2006-7230 pcre miscalculation of memory requirements if options are changed during pattern compilation

The MITRE CVE dictionary describes this issue as:

Perl-Compatible Regular Expression (PCRE) library before 7.0 does not properly calculate the amount of memory needed for a compiled regular expression pattern when the (1) -x or (2) -i UTF-8 options change within the pattern, which allows context-dependent attackers to cause a denial of service (PCRE or glibc crash) via crafted regular expressions.

Find out more about CVE-2006-7230 from the MITRE CVE dictionary dictionary and NIST NVD.

Red Hat Security Errata

Platform Errata Release Date
Red Hat Enterprise Linux 5 (pcre) RHSA-2007:1059 2007-11-29
Red Hat Enterprise Linux 4 (pcre) RHSA-2007:1068 2007-11-29

Acknowledgements

Red Hat would like to thank Ludwig Nussel for reporting this issue.

Last Modified

CVE description copyright © 2017, The MITRE Corporation

Close

Welcome! Check out the Getting Started with Red Hat page for quick tours and guides for common tasks.