CVE-2015-3217: Improper Restriction of Operations within the Bounds of a Memory Buffer
(updated )
PCRE, and PCRE2 mishandle group empty matches, which might allow remote attackers to cause a denial of service (stack-based buffer overflow) via a crafted regular expression.
References
Detect and mitigate CVE-2015-3217 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →