4 ms·
If I'm reading this right, the exploit is in the regex compilation stage, not the data matching stage; therefore remote exploitation would require the server se
by warbiscuit 11y ago
If I'm reading this right, the exploit is in the regex compilation stage, not the data matching stage; therefore remote exploitation would require the server setup to compile attacker-provided regexps, not just setup to run attacker data through an admin-configured regexp?
If that's the case, a typical nginx/apache config shouldn't be remotely vulnerable, right? Though I could see some shared hosting scenarios having some issues.
- TheLoneWolfling 11y agoSimple searches could be an issue, however.
- pg_is_a_butt 11y agosimple searches would be escaped... in PHP's implementation of PCRE, you'd use the preg_quote function... you should never execute raw user data as a regex.
- duaneb 11y agoNot everyone quotes the things they put into regular expressions. Before that would have resulted in incorrect code, but now it's a security vulnerability.