pcregrep in PCRE before 8.38 mishandles the -q option for binary files, which might allow remote attackers to obtain sensitive information via a crafted file, as demonstrated by a CGI script that sends stdout data to a client.
References
Configurations
History
No history.
Information
Published : 2015-12-02 01:59
Updated : 2025-04-12 10:46
NVD link : CVE-2015-8393
Mitre link : CVE-2015-8393
CVE.ORG link : CVE-2015-8393
JSON object : View
Products Affected
fedoraproject
- fedora
php
- php
pcre
- perl_compatible_regular_expression_library
CWE
CWE-200
Exposure of Sensitive Information to an Unauthorized Actor