CVE-2020-14155

libpcre in PCRE before 8.44 allows an integer overflow via a large number after a (?C substring.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
5.3 MEDIUM
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
mitreCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 37%
VendorProductVersion
pcrepcre
𝑥
< 8.44
applemacos
𝑥
< 11.0.1
gitlabgitlab
𝑥
< 12.10.13
gitlabgitlab
𝑥
< 12.10.13
gitlabgitlab
13.0.0 ≤
𝑥
< 13.0.8
gitlabgitlab
13.0.0 ≤
𝑥
< 13.0.8
gitlabgitlab
13.1.0 ≤
𝑥
< 13.1.2
gitlabgitlab
13.1.0 ≤
𝑥
< 13.1.2
oraclecommunications_cloud_native_core_policy
1.15.0
netappactive_iq_unified_manager
-
netappcloud_backup
-
netappclustered_data_ontap
-
netappontap_select_deploy_administration_utility
-
netappsteelstore_cloud_integrated_storage
-
netapph410c_firmware
-
netapph300s_firmware
-
netapph500s_firmware
-
netapph700s_firmware
-
netapph410s_firmware
-
splunkuniversal_forwarder
8.2.0 ≤
𝑥
< 8.2.12
splunkuniversal_forwarder
9.0.0 ≤
𝑥
< 9.0.6
splunkuniversal_forwarder
9.1.0
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
pcre3
bullseye
2:8.39-13
fixed
buster
no-dsa
stretch
no-dsa
jessie
no-dsa
bookworm
2:8.39-15
fixed
sid
2:8.39-15.1
fixed
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
pcre3
jammy
not-affected
impish
not-affected
hirsute
not-affected
groovy
not-affected
focal
Fixed 2:8.39-12ubuntu0.1
released
eoan
ignored
bionic
Fixed 2:8.39-9ubuntu0.1
released
xenial
Fixed 2:8.38-3.1ubuntu0.1~esm1
released
trusty
Fixed 1:8.31-2ubuntu2.3+esm1
released