CVE-2016-3191
The compile_branch function in pcre_compile.c in PCRE 8.x before 8.39 and pcre2_compile.c in PCRE2 before 10.22 mishandles patterns containing an (*ACCEPT) substring in conjunction with nested parentheses, which allows remote attackers to execute arbitrary code or cause a denial of service (stack-based buffer overflow) via a crafted regular expression, as demonstrated by a JavaScript RegExp object encountered by Konqueror, aka ZDI-CAN-3542.
- Pcre
- = 8.00, 8.01, 8.02, 8.10, 8.11, 8.12, 8.13, 8.20, 8.21, 8.30, 8.31, 8.32, 8.33, 8.34, 8.35, 8.36, 8.37, 8.38
- Pcre pcre2
- ≤ 10.21
- Fix
- Available
- CVSS 3.0
- 9.8 CRITICAL
- EPSS
- 8.4% (94th percentile)
- Weakness
- CWE-119
- NVD status
- Modified
- Published
- 2016-03-17
CVE-2016-3191 at NVD
No indexed exploits for CVE-2016-3191 yet
Our index is partial: it proves presence, never absence
No exploit for CVE-2016-3191 has been indexed yet. Our index is built from live traffic and upstream syncs, so this page can only say what it knows — not that no exploit exists.