CVE-2020-14155
⚪ Do wiadomości
Przepełnienie całkowite w libpcre umożliwia zdalne wykonanie kodu.
CVSS
5.3
EPSS
4.2%
Exploit
none
Vendor
netapp
Opis źródłowy (NVD)
libpcre in PCRE before 8.44 allows an integer overflow via a large number after a (?C substring.
brak
Brak patcha
Źródła i daty
| Źródło | Wartość |
|---|---|
| NVD – CVSS | 5.3 |
| CISA KEV (aktywnie wykorzystywane) | Nie |
| FIRST EPSS (prawdopodobieństwo exploita) | 4.2% |
| Opublikowano (NVD) | 2020-06-15 17:15:10 UTC |
| Ostatnia modyfikacja (NVD) | 2026-10-08 21:17:23 UTC |
Referencje
- http://seclists.org/fulldisclosure/2020/Dec/32 ([email protected]) [Mailing List, Third Party Advisory]
- http://seclists.org/fulldisclosure/2021/Feb/14 ([email protected]) [Mailing List, Third Party Advisory]
- https://about.gitlab.com/releases/2020/07/01/security-release-13-1-2-release/ ([email protected]) [Third Party Advisory]
- https://bugs.gentoo.org/717920 ([email protected]) [Issue Tracking, Patch, Third Party Advisory]
- https://lists.apache.org/thread.html/rf9fa47ab66495c78bb4120b0754dd9531ca2ff0430f6685ac9b07772%40%3Cdev.mina.apache.org%3E ([email protected]) [Mailing List, Third Party Advisory]
- https://security.netapp.com/advisory/ntap-20221028-0010/ ([email protected]) [Third Party Advisory]
- https://support.apple.com/kb/HT211931 ([email protected]) [Third Party Advisory]
- https://support.apple.com/kb/HT212147 ([email protected]) [Third Party Advisory]
- https://www.oracle.com/security-alerts/cpuapr2022.html ([email protected]) [Patch, Third Party Advisory]
- https://www.pcre.org/original/changelog.txt ([email protected]) [Release Notes, Vendor Advisory]