Description
PCRE before 8.38 mishandles the [: and \\ substrings in character classes, which allows remote attackers to cause a denial of service (uninitialized memory read) or possibly have unspecified other impact via a crafted regular expression, as demonstrated by a JavaScript RegExp object encountered by Konqueror.
Remediation
References
Related Vulnerabilities
phpMyAdmin Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2016-6613)
Drupal Core 5.x HTTP Response Splitting (5.0 - 5.2)
WeBid Improper Control of Generation of Code ('Code Injection') Vulnerability (CVE-2023-47397)
WordPress Plugin WordPress Bitcoin Payments-Blockonomics Cross-Site Scripting (3.2)
WordPress Deserialization of Untrusted Data Vulnerability (CVE-2020-36326)