Alerts This Week
Warning Icon 1 916
Alerts This Week
Warning Icon 1 916

Fedora 22: 2015-14235 Critical: Pcre Heap Overflow Issue

fedora
Calendar Grey September 11, 2015
Dist Fedora Esm H88
Fedora 22 refreshes pcre to resolve buffer overflow vulnerability in named references pertaining to regex patterns.
This release fixes a heap overflow when compiling certain regular expressions with named refecences.

Summary

Perl-compatible regular expression library.

PCRE has its own native API, but a set of "wrapper" functions that are based on

the POSIX API are also supplied in the library libpcreposix. Note that this

just provides a POSIX calling interface to PCRE: the regular expressions

themselves still follow Perl syntax and semantics. The header file

for the POSIX-style functions is called pcreposix.h.

Update Information:

This release fixes a heap overflow when compiling certain regular expressions with named refecences.

Change Log

References


[ 1 ] Bug #1256449 - pcre: Heap Overflow in compile_regex() https://bugzilla.redhat.com/show_bug.cgi?id=1256449

Update Instructions

This update can be installed with the "yum" update program. Use su -c 'yum update pcre' at the command line. For more information, refer to "Managing Software with yum", available at .

Severity
critical
Lowest
Low
Medium
High
Critical

Name: pcre
Product: Fedora 22
Version: 8.37
Release: 4.fc22
URL: /
Summary: Perl-compatible regular expression library

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here