Description
The pcre_compile function in pcre_compile.c in PCRE before 8.38 mishandles certain [: nesting, which allows remote attackers to cause a denial of service (CPU consumption) or possibly have unspecified other impact via a crafted regular expression, as demonstrated by a JavaScript RegExp object encountered by Konqueror.
Remediation
References
Related Vulnerabilities
WordPress Plugin All-in-One Event Calendar Multiple Vulnerabilities (1.10-standard)
Moodle Improper Input Validation Vulnerability (CVE-2011-4302)
Oracle Database Server CVE-2009-1020 Vulnerability (CVE-2009-1020)
Ruby on Rails Use of Externally-Controlled Format String Vulnerability (CVE-2013-4389)