CVE-2007-1661
EPSS 2.0%
Description
Perl-Compatible Regular Expression (PCRE) library before 7.3 backtracks too far when matching certain input bytes against some regex patterns in non-UTF-8 mode, which allows context-dependent attackers to obtain sensitive information or cause a denial of service (crash), as demonstrated by the "\X?\d" and "\P{L}?\d" patterns.
How to fix CVE-2007-1661
To remediate CVE-2007-1661, upgrade the affected package to a fixed version below.
- Debian/glib2.0—upgrade to 2.14.3-1 or later
- Debian/pcre3—upgrade to 7.3-1 or later
Is CVE-2007-1661 being exploited?
Low — EPSS is 2.0%, meaning exploitation activity has not been observed at scale.
Affected packages (2)
- from 0, < 2.14.3-1
- from 0, < 7.3-1