PCRE before 8.36 mishandles the /(((a2)|(a*)g<-1>))*/ pattern and related patterns with certain internal recursive back references, which allows remote attackers to cause a denial of service (segmentation fault) or possibly have unspecified other impact via a crafted regular expression, as demonstrated by a JavaScript RegExp object encountered by Konqueror.
Source: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-2327
Reference (s):
- BID:74924
- URL: http://www.securityfocus.com/bid/74924
- http://vcs.pcre.org/pcre/code/trunk/ChangeLog?view=markup
- https://bugs.exim.org/show_bug.cgi?id=1503
- https://jira.mongodb.org/browse/SERVER-17252

