CVE-2015-2305

Related Vulnerabilities: CVE-2015-2305  

A heap buffer overflow flaw was found in the regcomp() function of Henry Spencer's regular expression library. An attacker able to make an application process a specially crafted regular expression pattern with the regcomp() function could cause that application to crash and possibly execute arbitrary code.

A heap buffer overflow flaw was found in the regcomp() function of Henry Spencer's regular expression library. An attacker able to make an application process a specially crafted regular expression pattern with the regcomp() function could cause that application to crash and possibly execute arbitrary code.

Find out more about CVE-2015-2305 from the MITRE CVE dictionary dictionary and NIST NVD.

CVSS v2 metrics

Base Score 5.1
Base Metrics AV:N/AC:H/Au:N/C:P/I:P/A:P
Access Vector Network
Access Complexity High
Authentication None
Confidentiality Impact Partial
Integrity Impact Partial
Availability Impact Partial

Find out more about Red Hat support for the Common Vulnerability Scoring System (CVSS).

Red Hat Security Errata

Platform Errata Release Date
Red Hat Software Collections for Red Hat Enterprise Linux 7 (php54-php) RHSA-2015:1066 2015-06-04
Red Hat Software Collections for Red Hat Enterprise Linux 6 (php54-php) RHSA-2015:1066 2015-06-04
Red Hat Software Collections for Red Hat Enterprise Linux 7 (php55-php) RHSA-2015:1053 2015-06-04
Red Hat Software Collections for Red Hat Enterprise Linux 6 (php55-php) RHSA-2015:1053 2015-06-04

Affected Packages State

Platform Package State
Red Hat Software Collections for Red Hat Enterprise Linux rh-php56-php Not affected
Red Hat Software Collections for Red Hat Enterprise Linux rh-mariadb100-mariadb Will not fix
Red Hat Software Collections 1 for Red Hat Enterprise Linux mysql55-mysql Will not fix
Red Hat Software Collections 1 for Red Hat Enterprise Linux mariadb55-mariadb Will not fix
Red Hat Enterprise Linux 7 php Fix deferred
Red Hat Enterprise Linux 7 mesa-private-llvm Not affected
Red Hat Enterprise Linux 7 mariadb Will not fix
Red Hat Enterprise Linux 6 mesa-private-llvm Not affected
Red Hat Enterprise Linux 6 mysql Will not fix
Red Hat Enterprise Linux 6 php Fix deferred
Red Hat Enterprise Linux 5 php53 Will not fix
Red Hat Enterprise Linux 5 mysql Will not fix
Red Hat Enterprise Linux 5 mysql55-mysql Will not fix
Red Hat Enterprise Linux 5 mysql51-mysql Will not fix
Red Hat Enterprise Linux 5 php Will not fix