Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 524
Alerts This Week
Warning Icon 1 524

Fedora 23: pcre Security Update - Critical Buffer Overflow Fix

fedora
Calendar Grey November 26, 2015
Scroller Fedora
Fedora 24 announces a patch for glibc tackling vulnerabilities and a significant stack buffer overflow problem that bolsters overall system integrity.
This release fixes various bugs when compiling or matching expressions

Summary

Perl-compatible regular expression library.

PCRE has its own native API, but a set of "wrapper" functions that are based on

the POSIX API are also supplied in the library libpcreposix. Note that this

just provides a POSIX calling interface to PCRE: the regular expressions

themselves still follow Perl syntax and semantics. The header file

for the POSIX-style functions is called pcreposix.h.

Update Information:

This release fixes various bugs when compiling or matching expressions. It also fixes how pcregrep handles binary files. It also fixes a heap-based buffer overflow in pcre_exec() when ovector has size 1 (bug #1285415)

Change Log

References


[ 1 ] Bug #1285413 - pcre: Heap-based buffer overflow in pcre_exec https://bugzilla.redhat.com/show_bug.cgi?id=1285413

Update Instructions

This update can be installed with the "yum" update program. Use su -c 'yum update pcre' at the command line. For more information, refer to "Managing Software with yum", available at .

Severity
critical
Lowest
Low
Medium
High
Critical

Name: pcre
Product: Fedora 23
Version: 8.38
Release: 1.fc23
URL:
Summary: Perl-compatible regular expression library

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.