Back to Database
Status published
Medium
CVE-2020-14155
libpcre in PCRE before 8.44 allows an integer overflow via...
Vulnerability Description
libpcre in PCRE before 8.44 allows an integer overflow via a large number after a (?C substring.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
THREAT MONITOR
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2020-14155
Credits & Attribution
No credits recorded in the NVD database.
References
- https://bugs.gentoo.org/717920
- https://www.pcre.org/original/changelog.txt
- http://seclists.org/fulldisclosure/2020/Dec/32
- https://support.apple.com/kb/HT211931
- http://seclists.org/fulldisclosure/2021/Feb/14
- https://lists.apache.org/thread.html/rf9fa47ab66495c78bb4120b0754dd9531ca2ff0430f6685ac9b07772%40%3Cdev.mina.apache.org%3E
- https://support.apple.com/kb/HT212147
- https://www.oracle.com/security-alerts/cpuapr2022.html
- https://about.gitlab.com/releases/2020/07/01/security-release-13-1-2-release/
- https://security.netapp.com/advisory/ntap-20221028-0010/
More from pcre
View All →CVE-2022-41409
Integer overflow vulnerability in pcre2test before 10.41 allows attackers to...
High
7.5
CVE-2019-20838
libpcre in PCRE before 8.43 allows a subject buffer over-read...
High
7.5
CVE-2019-20454
An out-of-bounds read was discovered in PCRE before 10.34 when...
Medium
5.1
CVE-2017-8786
pcre2test.c in PCRE2 10.23 allows remote attackers to cause a...
Critical
9.8
CVE-2017-8399
PCRE2 before 10.30 has an out-of-bounds write caused by a...
Critical
9.8
Affected Vendor
pcre
View all reports →Affected Software
pcre, macos, gitlab, communications cloud native core policy, active iq unified manager, cloud backup, clustered data ontap, ontap select deploy administration utility, steelstore cloud integrated storage, h410c firmware, h300s firmware, h500s firmware, h700s firmware, h410s firmware, universal forwarder
Vulnerable Versions:
0, 13.0.0, 13.1.0, 1.15.0, 8.2.0, 9.0.0, 9.1.0
Timeline
Official Publish:
June 15th, 2020
Last Modified:
August 4th, 2024
Added to House:
July 21st, 2026
CVSS Vectors
V3:
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
Weaknesses (CWE)
No CWE data available
MITRE ATT&CK TTPs
No associated TTPs found for this vulnerability.