Alerts This Week
Warning Icon 1 770
Alerts This Week
Warning Icon 1 770

Fedora 25: 2017-b4d4a46af6 Moderate: PCRE Crash and Buffer Overflow

fedora
Calendar Grey April 25, 2017
Dist Fedora Esm H88
Fedora 25 now has an important security patch that resolves serious vulnerabilities found in the PCRE library, which could lead to application crashes and potential buffer overflow exploits.
This release fixes a crash when finding a Unicode property for a character with a code point greater than 0x10ffff in UTF-32 library while UTF mode is disabled and JIT mde enabled

Summary

PCRE, Perl-compatible regular expression, library has its own native API, but

a set of wrapper functions that are based on the POSIX API are also supplied

in the libpcreposix library. Note that this just provides a POSIX calling

interface to PCRE: the regular expressions themselves still follow Perl syntax

and semantics. This package provides support for strings in 8-bit and UTF-8

encodings. Detailed change log is provided by pcre-doc package.

This release fixes a crash when finding a Unicode property for a character with

a code point greater than 0x10ffff in UTF-32 library while UTF mode is disabled

and JIT mde enabled. It also fixes a buffer overlflow in pcretest tool when

copying a string in UTF-32 mode.

[ 1 ] Bug #1434504 - CVE-2017-7186 pcre: Invalid Unicode property lookup (8.41/7, 10.24/2)

https://bugzilla.redhat.com/show_bug.cgi?id=1434504

su -c 'dnf upgrade pcre' at the command line.

For more information, refer to the dnf documentation available at

https://dnf.readthedocs.io/en/latest/command_ref.html

All packages are signed with the Fedora Project GPG key. More details on the

GPG keys used by the Fedora Project can be found at

https://fedoraproject.org/security/

package-announce mailing list -- package-announce@lists.fedoraproject.org

To unsubscribe send an email to package-announce-leave@lists.fedoraproject.org

Change Log

References

Update Instructions

Product: Fedora 25
Version: 8.40
Release: 7.fc25
URL: /
Summary: Perl-compatible regular expression library

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here