Vulnerabilities > CVE-2016-9954 - Resource Management Errors vulnerability in Irregex Project Irregex
Attack vector
NETWORK Attack complexity
LOW Privileges required
NONE Confidentiality impact
NONE Integrity impact
NONE Availability impact
HIGH Summary
The backtrack compilation code in the Irregex package (aka IrRegular Expressions) before 0.9.6 for Scheme allows remote attackers to cause a denial of service (memory consumption) via a crafted regular expression with a repeating pattern.
Vulnerable Configurations
Common Weakness Enumeration (CWE)
Nessus
NASL family | FreeBSD Local Security Checks |
NASL id | FREEBSD_PKG_C6932DD4EAFF11E69AC1A4BADB2F4699.NASL |
description | Peter Bex reports : A buffer overflow error was found in the POSIX unit |
last seen | 2020-06-01 |
modified | 2020-06-02 |
plugin id | 96995 |
published | 2017-02-06 |
reporter | This script is Copyright (C) 2017-2018 and is owned by Tenable, Inc. or an Affiliate thereof. |
source | https://www.tenable.com/plugins/nessus/96995 |
title | FreeBSD : chicken -- multiple vulnerabilities (c6932dd4-eaff-11e6-9ac1-a4badb2f4699) |
code |
|
References
- http://www.openwall.com/lists/oss-security/2016/12/15/8
- http://www.openwall.com/lists/oss-security/2016/12/15/8
- http://www.securityfocus.com/bid/94942
- http://www.securityfocus.com/bid/94942
- https://bugzilla.redhat.com/show_bug.cgi?id=1413990
- https://bugzilla.redhat.com/show_bug.cgi?id=1413990
- https://github.com/ashinn/irregex/commit/a16ffc86eca15fca9e40607d41de3cea9cf868f1
- https://github.com/ashinn/irregex/commit/a16ffc86eca15fca9e40607d41de3cea9cf868f1