Alerts This Week
Warning Icon 1 659
Alerts This Week
Warning Icon 1 659

Debian: DSA-1499-1 Critical: PCRE Buffer Overflow Exploit Mitigation

debian
Calendar Grey February 19, 2008
Debian Logo
Patch addressing arbitrary code execution vulnerabilities in the PCRE library via regex patterns in Debian Security Advisory DSA-1499-1.
It was discovered that specially crafted regular expressions involving codepoints greater than 255 could cause a buffer overflow in the PCRE library (CVE-2008-0674).

Summary


For the old stable distribution (sarge), this problem has been fixed in
version 4.5+7.4-2.

For the unstable distribution, thi problem has been fixed in version
7.6-1.

We recommend that you upgrade your pcre3 package.

Upgrade instructions
- --------------------wget url
will fetch the file for you
dpkg -i file.deb
will install the referenced file.

If you are using the apt-get package manager, use the line for
sources.list as given below:

apt-get update
will update the internal database
apt-get upgrade
will install corrected packages

You may use an automated update by adding the resources from the
footer to the proper configuration.


Debian GNU/Linux 3.1 alias sarge

Size/MD5 checksum: 99934 750cb82053d0d184e96b6f2256b07259
Size/MD5 checksum: 883 6d7166721448553dfe9672bdbb6c75c2
Size/MD5 checksum: 1106897 de886b22cddc8eaf620a421d3041ee0b

Architecture independent packages:

Size/MD5 checksum: 764 f45e8c3460a8...

Read the Full Advisory

Severity
critical
Lowest
Low
Medium
High
Critical

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here