---
cve: "CVE-2017-7186"
severity: "LOW"
cvss: 3.1
epss: "5%"
vendor: "n/a"
kev: false
exploited: false
published: "2017-03-20 00:59:00"
tags: [cve, security, low]
source: tsecurity.de CVE-Dossier
exported: "2026-09-17T08:21:41+02:00"
---

# CVE-2017-7186

> 3.1 LOW

## Beschreibung

libpcre1 in PCRE 8.40 and libpcre2 in PCRE2 10.23 allow remote attackers to cause a denial of service (segmentation violation for read access, and application crash) by triggering an invalid Unicode property lookup.

## Referenzen

- <https://bugs.exim.org/show_bug.cgi?id=2052>
- <https://security.gentoo.org/glsa/201710-09>
- <https://vcs.pcre.org/pcre/code/trunk/pcre_internal.h?r1=1649&r2=1688&sortby=date>
- <https://vcs.pcre.org/pcre2/code/trunk/src/pcre2_internal.h?r1=600&r2=670&sortby=date>
- <https://vcs.pcre.org/pcre/code/trunk/pcre_ucd.c?r1=1490&r2=1688&sortby=date>
- <http://www.securityfocus.com/bid/97030>
- <https://blogs.gentoo.org/ago/2017/03/14/libpcre-invalid-memory-read-in-match-pcre_exec-c/>
- <https://vcs.pcre.org/pcre2/code/trunk/src/pcre2_ucd.c?r1=316&r2=670&sortby=date>
- <https://access.redhat.com/errata/RHSA-2018:2486>
- <https://security.gentoo.org/glsa/201710-25>

---
_Exportiert aus dem [tsecurity.de CVE-Dossier](https://tsecurity.de/cve?cve=CVE-2017-7186) · Datenquellen: EUVD (ENISA), NVD, OSV, CISA KEV, FIRST EPSS, Exploit-DB, BSI BITS_
