Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
Perl-Compatible Regular Expression (PCRE) library before 7.3 backtracks too far when matching certain input bytes against some regex patterns in non-UTF-8 mode, which allows context-dependent attackers to obtain sensitive information or cause a denial of service (crash), as demonstrated by the "\X?\d" and "\P{L}?\d" patterns.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
PCRE正则表达式库敏感信息泄露漏洞
Vulnerability Description
PCRE(Perl Compatible Regular Expressions)是软件开发者Philip Hazel所研发的一个使用C语言编写的开源正则表达式函数库。 pcre处理某些畸形正则表达式的方法存在信息泄露漏洞,非UTF-8模式的多种\X?\d或\P{L}?\d形式可能回退到字符串开始之前,这可能造成泄露地址空间地址或由于越界读取而出现崩溃。
CVSS Information
N/A
Vulnerability Type
N/A