Stack Exhaustion Vulnerability in PCRE 8.41's OP_KETRMAX Feature

Stack Exhaustion Vulnerability in PCRE 8.41's OP_KETRMAX Feature

CVE-2017-11164 · HIGH Severity

AV:N/AC:L/AU:N/C:N/I:N/A:C

In PCRE 8.41, the OP_KETRMAX feature in the match function in pcre_exec.c allows stack exhaustion (uncontrolled recursion) when processing a crafted regular expression.

Learn more about our Web Application Penetration Testing UK.