oss-sec mailing list archives

Re: Re: Heap Overflow in PCRE


From: Tomas Hoger <thoger () redhat com>
Date: Mon, 30 Nov 2015 09:43:25 +0100

On Sun, 29 Nov 2015 05:58:01 -0500 (EST) cve-assign () mitre org wrote:

JavaScript may be "something else" in most cases, e.g.,

  http://blog.chromium.org/2009/02/irregexp-google-chromes-new-regexp.html
  https://github.com/v8/v8/tree/master/src/regexp
  https://hg.mozilla.org/mozilla-central/file/tip/js/src/irregexp

KDE/Konqueror uses pcre for JS regexps.

http://lxr.kde.org/source/kde/kdelibs/kjs/regexp.cpp?v=stable-qt4

-- 
Tomas Hoger / Red Hat Product Security


Current thread: