Files
cve/2015/CVE-2015-8386.md
2025-09-29 21:09:30 +02:00

906 B

CVE-2015-8386

Description

PCRE before 8.38 mishandles the interaction of lookbehind assertions and mutually recursive subpatterns, which allows remote attackers to cause a denial of service (buffer overflow) or possibly have unspecified other impact via a crafted regular expression, as demonstrated by a JavaScript RegExp object encountered by Konqueror.

POC

Reference

Github