Vulnerability Name:

CVE-2017-6004 (CCN-122097)

Assigned:2017-02-16
Published:2017-02-16
Updated:2021-06-29
Summary:The compile_bracket_matchingpath function in pcre_jit_compile.c in PCRE through 8.x before revision 1680 (e.g., the PHP 7.1.1 bundled version) allows remote attackers to cause a denial of service (out-of-bounds read and application crash) via a crafted regular expression.
CVSS v3 Severity:7.5 High (CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H)
6.7 Medium (Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:P/RL:O/RC:C)
Exploitability Metrics:Attack Vector (AV): Network
Attack Complexity (AC): Low
Privileges Required (PR): None
User Interaction (UI): None
Scope:Scope (S): Unchanged
Impact Metrics:Confidentiality (C): None
Integrity (I): None
Availibility (A): High
6.2 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H)
5.6 Medium (CCN Temporal CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:P/RL:O/RC:C)
Exploitability Metrics:Attack Vector (AV): Local
Attack Complexity (AC): Low
Privileges Required (PR): None
User Interaction (UI): None
Scope:Scope (S): Unchanged
Impact Metrics:Confidentiality (C): None
Integrity (I): None
Availibility (A): High
CVSS v2 Severity:5.0 Medium (CVSS v2 Vector: AV:N/AC:L/Au:N/C:N/I:N/A:P)
Exploitability Metrics:Access Vector (AV): Network
Access Complexity (AC): Low
Authentication (Au): None
Impact Metrics:Confidentiality (C): None
Integrity (I): None
Availibility (A): Partial
4.9 Medium (CCN CVSS v2 Vector: AV:L/AC:L/Au:N/C:N/I:N/A:C)
Exploitability Metrics:Access Vector (AV): Local
Access Complexity (AC): Low
Athentication (Au): None
Impact Metrics:Confidentiality (C): None
Integrity (I): None
Availibility (A): Complete
Vulnerability Type:CWE-125
Vulnerability Consequences:Denial of Service
References:Source: MITRE
Type: CNA
CVE-2017-6004

Source: CCN
Type: SECTRACK ID: 1037850
PCRE Logic Error in compile_bracket_matchingpath() Lets Remote Users Cause the Target Application to Crash

Source: CCN
Type: PCRE Web site
PCRE - Perl Compatible Regular Expressions

Source: BID
Type: UNKNOWN
96295

Source: CCN
Type: BID-96295
PCRE 'compile_bracket_matchingpath()' Function Denial of Service Vulnerability

Source: SECTRACK
Type: UNKNOWN
1037850

Source: REDHAT
Type: UNKNOWN
RHSA-2018:2486

Source: CONFIRM
Type: Issue Tracking, Third Party Advisory, VDB Entry
https://bugs.exim.org/show_bug.cgi?id=2035

Source: XF
Type: UNKNOWN
pcre-cve20176004-dos(122097)

Source: MLIST
Type: UNKNOWN
[bookkeeper-issues] 20210628 [GitHub] [bookkeeper] padma81 opened a new issue #2746: Security Vulnerabilities in CentOS 7 image, Upgrade image to CentOS 8

Source: GENTOO
Type: UNKNOWN
GLSA-201706-11

Source: CONFIRM
Type: Patch
https://vcs.pcre.org/pcre/code/trunk/pcre_jit_compile.c?r1=1676&r2=1680&view=patch

Source: CCN
Type: IBM Security Bulletin 6551876 (Cloud Pak for Security)
Cloud Pak for Security uses packages that are vulnerable to multiple CVEs

Source: CCN
Type: WhiteSource Vulnerability Database
CVE-2017-6004

Vulnerable Configuration:Configuration 1:
  • cpe:/a:pcre:pcre:*:*:*:*:*:*:*:* (Version <= 8.38)

  • Configuration CCN 1:
  • cpe:/a:pcre:pcre:8.38:*:*:*:*:*:*:*
  • AND
  • cpe:/a:ibm:cloud_pak_for_security:1.7.2.0:*:*:*:*:*:*:*

  • * Denotes that component is vulnerable
    Oval Definitions
    Definition IDClassTitleLast Modified
    oval:org.opensuse.security:def:20176004
    V
    CVE-2017-6004
    2023-06-22
    oval:org.opensuse.security:def:7640
    P
    libpcre1-32bit-8.45-150000.20.13.1 on GA media (Moderate)
    2023-06-12
    oval:org.opensuse.security:def:51980
    P
    Security update for sudo (Important)
    2023-01-20
    oval:org.opensuse.security:def:772
    P
    Security update for oniguruma (Important)
    2022-09-21
    oval:org.opensuse.security:def:93828
    P
    (Moderate)
    2022-07-06
    oval:org.opensuse.security:def:3054
    P
    dosfstools-3.0.26-6.5 on GA media (Moderate)
    2022-06-28
    oval:org.opensuse.security:def:94684
    P
    libpcre1-32bit-8.45-20.10.1 on GA media (Moderate)
    2022-06-22
    oval:org.opensuse.security:def:177
    P
    libpcre1-32bit-8.41-4.20 on GA media (Moderate)
    2022-06-13
    oval:org.opensuse.security:def:176
    P
    libpcap-devel-1.9.1-1.33 on GA media (Moderate)
    2022-06-13
    oval:org.opensuse.security:def:465
    P
    Security update for pcp (Moderate)
    2022-05-03
    oval:org.opensuse.security:def:112762
    P
    libpcre1-32bit-8.45-1.2 on GA media (Moderate)
    2022-01-17
    oval:org.opensuse.security:def:69759
    P
    Security update for python-Pygments (Important)
    2021-12-01
    oval:org.opensuse.security:def:89474
    P
    Security update for pcre (Moderate)
    2021-11-10
    oval:org.opensuse.security:def:33996
    P
    Security update for pcre (Moderate)
    2021-11-10
    oval:org.opensuse.security:def:85762
    P
    Security update for pcre (Moderate)
    2021-11-10
    oval:org.opensuse.security:def:30145
    P
    Security update for pcre (Moderate)
    2021-11-10
    oval:org.opensuse.security:def:19518
    P
    Security update for pcre (Moderate)
    2021-11-10
    oval:org.opensuse.security:def:59819
    P
    Security update for pcre (Moderate)
    2021-11-10
    oval:org.opensuse.security:def:125100
    P
    Security update for pcre (Moderate)
    2021-11-10
    oval:org.opensuse.security:def:55968
    P
    Security update for pcre (Moderate)
    2021-11-10
    oval:org.opensuse.security:def:88215
    P
    Security update for pcre (Moderate)
    2021-11-10
    oval:org.opensuse.security:def:32214
    P
    Security update for pcre (Moderate)
    2021-11-10
    oval:org.opensuse.security:def:83472
    P
    Security update for pcre (Moderate)
    2021-11-10
    oval:org.opensuse.security:def:23992
    P
    Security update for pcre (Moderate)
    2021-11-10
    oval:org.opensuse.security:def:58037
    P
    Security update for pcre (Moderate)
    2021-11-10
    oval:org.opensuse.security:def:5149
    P
    Security update for pcre (Moderate)
    2021-11-10
    oval:org.opensuse.security:def:51688
    P
    Security update for pcre (Moderate)
    2021-11-10
    oval:org.opensuse.security:def:34588
    P
    Security update for pcre (Moderate)
    2021-11-10
    oval:org.opensuse.security:def:86165
    P
    Security update for pcre (Moderate)
    2021-11-10
    oval:org.opensuse.security:def:30265
    P
    Security update for pcre (Moderate)
    2021-11-10
    oval:org.opensuse.security:def:19568
    P
    Security update for pcre (Moderate)
    2021-11-10
    oval:org.opensuse.security:def:60411
    P
    Security update for pcre (Moderate)
    2021-11-10
    oval:org.opensuse.security:def:125625
    P
    Security update for pcre (Moderate)
    2021-11-10
    oval:org.opensuse.security:def:56088
    P
    Security update for pcre (Moderate)
    2021-11-10
    oval:org.opensuse.security:def:88532
    P
    Security update for pcre (Moderate)
    2021-11-10
    oval:org.opensuse.security:def:33040
    P
    Security update for pcre (Moderate)
    2021-11-10
    oval:org.opensuse.security:def:84232
    P
    Security update for pcre (Moderate)
    2021-11-10
    oval:org.opensuse.security:def:26162
    P
    Security update for pcre (Moderate)
    2021-11-10
    oval:org.opensuse.security:def:58863
    P
    Security update for pcre (Moderate)
    2021-11-10
    oval:org.opensuse.security:def:6306
    P
    Security update for pcre (Moderate)
    2021-11-10
    oval:org.opensuse.security:def:35276
    P
    Security update for pcre (Moderate)
    2021-11-10
    oval:org.opensuse.security:def:86678
    P
    Security update for pcre (Moderate)
    2021-11-10
    oval:org.opensuse.security:def:31298
    P
    Security update for pcre (Moderate)
    2021-11-10
    oval:org.opensuse.security:def:82650
    P
    Security update for pcre (Moderate)
    2021-11-10
    oval:org.opensuse.security:def:19617
    P
    Security update for pcre (Moderate)
    2021-11-10
    oval:org.opensuse.security:def:61099
    P
    Security update for pcre (Moderate)
    2021-11-10
    oval:org.opensuse.security:def:126792
    P
    Security update for pcre (Moderate)
    2021-11-10
    oval:org.opensuse.security:def:57121
    P
    Security update for pcre (Moderate)
    2021-11-10
    oval:org.opensuse.security:def:89216
    P
    Security update for pcre (Moderate)
    2021-11-10
    oval:org.opensuse.security:def:33738
    P
    Security update for pcre (Moderate)
    2021-11-10
    oval:org.opensuse.security:def:84690
    P
    Security update for pcre (Moderate)
    2021-11-10
    oval:org.opensuse.security:def:29443
    P
    Security update for pcre (Moderate)
    2021-11-10
    oval:org.opensuse.security:def:59561
    P
    Security update for pcre (Moderate)
    2021-11-10
    oval:org.opensuse.security:def:55266
    P
    Security update for pcre (Moderate)
    2021-11-10
    oval:org.opensuse.security:def:87504
    P
    Security update for pcre (Moderate)
    2021-11-10
    oval:org.opensuse.security:def:31701
    P
    Security update for pcre (Moderate)
    2021-11-10
    oval:org.opensuse.security:def:83352
    P
    Security update for pcre (Moderate)
    2021-11-10
    oval:org.opensuse.security:def:23700
    P
    Security update for pcre (Moderate)
    2021-11-10
    oval:org.opensuse.security:def:127189
    P
    Security update for pcre (Moderate)
    2021-11-10
    oval:org.opensuse.security:def:57524
    P
    Security update for pcre (Moderate)
    2021-11-10
    oval:org.opensuse.security:def:4285
    P
    Security update for pcre (Moderate)
    2021-11-10
    oval:org.opensuse.security:def:106234
    P
    Security update for grilo (Important)
    2021-10-06
    oval:org.opensuse.security:def:89709
    P
    libpcre1-32bit-8.41-4.20 on GA media (Moderate)
    2021-09-21
    oval:org.opensuse.security:def:61554
    P
    libpcre1-32bit-8.41-4.20 on GA media (Moderate)
    2021-09-21
    oval:org.opensuse.security:def:96674
    P
    libpcre1-32bit-8.41-4.20 on GA media (Moderate)
    2021-09-21
    oval:org.opensuse.security:def:71295
    P
    libpcre1-32bit-8.41-4.20 on GA media (Moderate)
    2021-09-21
    oval:org.opensuse.security:def:103364
    P
    libpcre1-32bit-8.41-4.20 on GA media (Moderate)
    2021-09-21
    oval:org.opensuse.security:def:47026
    P
    libgypsy0-0.9-6.22 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:46986
    P
    libQt5Concurrent5-5.6.1-11.7 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:47925
    P
    xlockmore-5.43-5.30 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:47985
    P
    curl-7.60.0-9.8 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:47250
    P
    eog-3.20.4-7.7 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:47001
    P
    libXv1-1.0.10-3.56 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:48112
    P
    libfreetype6-2.6.3-7.15.1 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:47612
    P
    fuse-2.9.3-6.3.1 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:47315
    P
    libXfont1-1.5.1-10.3 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:48214
    P
    libvdpau1-1.1.1-6.73 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:47758
    P
    libospf0-1.1.1-17.7.1 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:47539
    P
    yast2-3.2.36-1.11 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:47854
    P
    perl-XML-LibXML-2.0019-6.3.5 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:47901
    P
    tar-1.27.1-15.3.7 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:47158
    P
    stunnel-5.00-3.1 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:46987
    P
    libQt5WebKit5-5.6.1-9.4 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:48047
    P
    iputils-s20121221-2.17 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:47398
    P
    libproxy1-0.4.13-16.3 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:47122
    P
    perl-32bit-5.18.2-11.1 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:48143
    P
    liblouis-data-2.6.4-6.6.1 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:47696
    P
    libblkid1-2.29.2-7.14 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:47447
    P
    mozilla-nspr-32bit-4.13.1-18.1 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:47823
    P
    logwatch-7.4.3-15.65 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:47687
    P
    libXvMC1-1.0.8-7.1 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:71936
    P
    libpcre1-32bit-8.41-4.20 on GA media (Moderate)
    2021-08-09
    oval:org.opensuse.security:def:62195
    P
    libpcre1-32bit-8.41-4.20 on GA media (Moderate)
    2021-08-09
    oval:org.opensuse.security:def:100953
    P
    libpcre1-32bit-8.41-4.20 on GA media (Moderate)
    2021-08-09
    oval:org.opensuse.security:def:1106
    P
    libpcre1-32bit-8.41-4.20 on GA media (Moderate)
    2021-08-09
    oval:org.opensuse.security:def:69864
    P
    Security update for qemu (Important)
    2021-06-09
    oval:org.opensuse.security:def:48617
    P
    rsync-3.1.0-12.1 on GA media (Moderate)
    2021-06-08
    oval:org.opensuse.security:def:71006
    P
    libpcre1-32bit-8.41-4.20 on GA media (Moderate)
    2021-06-08
    oval:org.opensuse.security:def:48906
    P
    gnome-online-accounts-3.20.5-9.6 on GA media (Moderate)
    2021-06-08
    oval:org.opensuse.security:def:46698
    P
    libXRes1-1.0.7-3.54 on GA media (Moderate)
    2021-06-08
    oval:org.opensuse.security:def:46833
    P
    quagga-0.99.22.1-3.128 on GA media (Moderate)
    2021-06-08
    oval:org.opensuse.security:def:71065
    P
    pam-1.3.0-4.10 on GA media (Moderate)
    2021-06-08
    oval:org.opensuse.security:def:48563
    P
    libusbmuxd4-1.0.10-2.3 on GA media (Moderate)
    2021-06-08
    oval:org.opensuse.security:def:70952
    P
    libXinerama-devel-1.1.3-1.22 on GA media (Moderate)
    2021-06-08
    oval:org.opensuse.security:def:46697
    P
    libX11-6-1.6.2-4.12 on GA media (Moderate)
    2021-06-08
    oval:org.opensuse.security:def:48852
    P
    libfbembed2_5-2.5.2.26539-15.1 on GA media (Moderate)
    2021-06-08
    oval:org.opensuse.security:def:46712
    P
    libXxf86dga1-1.1.4-3.59 on GA media (Moderate)
    2021-06-08
    oval:org.opensuse.security:def:61265
    P
    libpcre1-32bit-8.41-4.20 on GA media (Moderate)
    2021-06-08
    oval:org.opensuse.security:def:64278
    P
    Security update for clamav (Moderate)
    2020-12-14
    oval:org.opensuse.security:def:66416
    P
    Security update for openssl-1_1 (Important)
    2020-12-09
    oval:org.opensuse.security:def:61861
    P
    libpcre1-32bit-8.41-4.20 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:100541
    P
    libpcre1-32bit-8.41-4.20 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:71602
    P
    libpcre1-32bit-8.41-4.20 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:107207
    P
    libpcre1-32bit-8.41-4.20 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:116765
    P
    libpcre1-32bit-8.41-4.20 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:49159
    P
    libblkid-devel on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:66508
    P
    libpcre1-32bit on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:67712
    P
    libpcre1-32bit on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:49213
    P
    libpcre1-32bit on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:73199
    P
    libpcre1-32bit on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:64365
    P
    libpcre1-32bit on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:67612
    P
    glibc-locale-32bit on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:73081
    P
    fuse on GA media (Moderate)
    2020-12-01
    oval:com.ubuntu.cosmic:def:201760040000000
    V
    CVE-2017-6004 on Ubuntu 18.10 (cosmic) - low.
    2017-02-16
    oval:com.ubuntu.artful:def:20176004000
    V
    CVE-2017-6004 on Ubuntu 17.10 (artful) - low.
    2017-02-16
    oval:com.ubuntu.trusty:def:20176004000
    V
    CVE-2017-6004 on Ubuntu 14.04 LTS (trusty) - low.
    2017-02-16
    oval:com.ubuntu.bionic:def:201760040000000
    V
    CVE-2017-6004 on Ubuntu 18.04 LTS (bionic) - low.
    2017-02-16
    oval:com.ubuntu.bionic:def:20176004000
    V
    CVE-2017-6004 on Ubuntu 18.04 LTS (bionic) - low.
    2017-02-16
    oval:com.ubuntu.xenial:def:20176004000
    V
    CVE-2017-6004 on Ubuntu 16.04 LTS (xenial) - low.
    2017-02-16
    oval:com.ubuntu.xenial:def:201760040000000
    V
    CVE-2017-6004 on Ubuntu 16.04 LTS (xenial) - low.
    2017-02-16
    oval:com.ubuntu.cosmic:def:20176004000
    V
    CVE-2017-6004 on Ubuntu 18.10 (cosmic) - low.
    2017-02-16
    oval:com.ubuntu.disco:def:201760040000000
    V
    CVE-2017-6004 on Ubuntu 19.04 (disco) - low.
    2017-02-16
    oval:com.ubuntu.precise:def:20176004000
    V
    CVE-2017-6004 on Ubuntu 12.04 LTS (precise) - low.
    2017-02-16
    BACK
    pcre pcre *
    pcre pcre 8.38
    ibm cloud pak for security 1.7.2.0