CVE-2017-6004

Related Vulnerabilities: CVE-2017-6004  

The compile_bracket_matchingpath function in pcre_jit_compile.c in PCRE through 8.x before revision 1680 (e.g., the PHP 7.1.1 bundled version) allows remote attackers to cause a denial of service (out-of-bounds read and application crash) via a crafted regular expression.

The MITRE CVE dictionary describes this issue as:

The compile_bracket_matchingpath function in pcre_jit_compile.c in PCRE through 8.x before revision 1680 (e.g., the PHP 7.1.1 bundled version) allows remote attackers to cause a denial of service (out-of-bounds read and application crash) via a crafted regular expression.

Find out more about CVE-2017-6004 from the MITRE CVE dictionary dictionary and NIST NVD.

CVSS v3 metrics

CVSS3 Base Score 7.5
CVSS3 Base Metrics CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Attack Vector Network
Attack Complexity Low
Privileges Required None
User Interaction None
Scope Unchanged
Confidentiality None
Integrity Impact None
Availability Impact High

Red Hat Security Errata

Platform Errata Release Date
Red Hat JBoss Core Services 1 RHSA-2018:2486 2018-08-16

Affected Packages State

Platform Package State
Red Hat Software Collections for Red Hat Enterprise Linux rh-mariadb101-mariadb Not affected
Red Hat Software Collections for Red Hat Enterprise Linux rh-php70-php Will not fix
Red Hat Software Collections for Red Hat Enterprise Linux rh-php56-php Not affected
Red Hat Software Collections for Red Hat Enterprise Linux rh-mariadb100-mariadb Not affected
Red Hat JBoss Web Server 3.0 httpd Will not fix
Red Hat JBoss Web Server 3 pcre Not affected
Red Hat JBoss EWS 2 httpd Will not fix
Red Hat JBoss EWS 1 httpd Will not fix
Red Hat Enterprise Linux 7 pcre Will not fix
Red Hat Enterprise Linux 7 virtuoso-opensource Not affected
Red Hat Enterprise Linux 7 glib2 Not affected
Red Hat Enterprise Linux 6 pcre Not affected
Red Hat Enterprise Linux 6 glib2 Not affected
Red Hat Enterprise Linux 5 pcre Not affected
Red Hat Directory Server 8 pcre Not affected