PCRE compile workspace overflow

看板Bugtraq作者時間15年前 (2010/05/07 02:48), 編輯推噓0(000)
留言0則, 0人參與, 最新討論串1/1
In versions of the PCRE regular expression library before 8.02, compiling a very large regular expression will overflow the workspace buffer. Although the code checks for the size of the compiled regular expression, the check only returns true after the end of the buffer has been overrun. The bug was fixed in PCRE 8.02 with this patch: http://vcs.pcre.org/viewvc/code/trunk/pcre_compile.c?r1=504&r2=505&view=patch This example will cause a 2 byte overflow: ~$ perl -e 'print "/","("x819, ")"x819, "/"' | pcretest Original Bug Report: http://bugs.exim.org/show_bug.cgi?id=962
文章代碼(AID): #1BumxaUF (Bugtraq)