Alerts This Week
Warning Icon 1 684
Alerts This Week
Warning Icon 1 684

Fedora 26: pcre Security Update - Moderate Buffer Overflow Fix

fedora
Calendar Grey May 1, 2017
Dist Fedora Esm H88
This patch resolves significant vulnerabilities in the pcre package for Fedora 26, eliminating potential crashes and safeguarding against buffer overruns.
This release fixes a crash when finding a Unicode property for a character with a code point greater than 0x10ffff in UTF-32 library while UTF mode is disabled and JIT mde enabled

Summary

PCRE, Perl-compatible regular expression, library has its own native API, but

a set of wrapper functions that are based on the POSIX API are also supplied

in the libpcreposix library. Note that this just provides a POSIX calling

interface to PCRE: the regular expressions themselves still follow Perl syntax

and semantics. This package provides support for strings in 8-bit and UTF-8

encodings. Detailed change log is provided by pcre-doc package.

This release fixes a crash when finding a Unicode property for a character with

a code point greater than 0x10ffff in UTF-32 library while UTF mode is disabled

and JIT mde enabled. It also fixes a buffer overlflow in pcretest tool when

copying a string in UTF-32 mode.

[ 1 ] Bug #1434504 - CVE-2017-7186 pcre: Invalid Unicode property lookup (8.41/7, 10.24/2)

https://bugzilla.redhat.com/show_bug.cgi?id=1434504

su -c 'dnf upgrade pcre' at the command line.

For more information, refer to the dnf documentation available at

https://dnf.readthedocs.io/en/latest/command_ref.html

All packages are signed with the Fedora Project GPG key. More details on the

GPG keys used by the Fedora Project can be found at

https://fedoraproject.org/security/

package-announce mailing list -- package-announce@lists.fedoraproject.org

To unsubscribe send an email to package-announce-leave@lists.fedoraproject.org

Change Log

References

Update Instructions

Product: Fedora 26
Version: 8.40
Release: 7.fc26
URL: /
Summary: Perl-compatible regular expression library

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here