Description
PCRE before 8.38 mishandles the /(?:|a|){100}x/ pattern and related patterns, which allows remote attackers to cause a denial of service (infinite recursion) or possibly have unspecified other impact via a crafted regular expression, as demonstrated by a JavaScript RegExp object encountered by Konqueror.
Remediation
References
Related Vulnerabilities
Joomla Improper Input Validation Vulnerability (CVE-2015-8562)
WordPress Plugin W3 Total Cache Multiple Vulnerabilities (0.9.4)
WordPress Plugin WP Intercom-Slack for WordPress Information Disclosure (1.2.1)
PHP Improper Input Validation Vulnerability (CVE-2007-3799)
WordPress Plugin Newsletters Multiple Vulnerabilities (4.6.14)