Alerts This Week
Warning Icon 1 727
Alerts This Week
Warning Icon 1 727

Fedora Core 3: 2005:802 Critical: Heap Overflow Risk In PCRE Library

fedora
Calendar Grey August 24, 2005
Dist Fedora Esm H88
Identified buffer overflow in pcre 4.5 leads to significant vulnerabilities in Fedora 3. Upgrade to address the defect.
Updated package.

Summary

Perl-compatible regular expression library. PCRE has its own native

API, but a set of "wrapper" functions that are based on the POSIX API

are also supplied in the library libpcreposix. Note that this just

provides a POSIX calling interface to PCRE; the regular expressions

themselves still follow Perl syntax and semantics. The header file for

the POSIX-style functions is called pcreposix.h.

the new package includes a fix for a heap buffer overflow.

- backport patch to fix heap overflow, CAN-2005-2491, #166330

cfca595b559afe8d33cbc39ab744d6db SRPMS/pcre-4.5-3.1.1.fc3.src.rpm

9f498d84c73b744cd03b2b93aca582c6 x86_64/pcre-4.5-3.1.1.fc3.x86_64.rpm

344d94e5b5b64c6422c71fec331dd94c x86_64/pcre-devel-4.5-3.1.1.fc3.x86_64.rpm

08efe09b0a59fcff8df2b42a1b64309a x86_64/debug/pcre-debuginfo-4.5-3.1.1.fc3.x86_64.rpm

81729fbca4064dd687bab07ae6cf9fd1 x86_64/pcre-4.5-3.1.1.fc3.i386.rpm

81729fbca4064dd687bab07ae6cf9fd1 i386/pcre-4.5-3.1.1.fc3.i386.rpm

35b406ce33a16b67b73a600ab5cb5b3e i386/pcre-devel-4.5-3.1.1.fc3.i386.rpm

14c8d8b5d8dec038bd54f9e16668d5da i386/debug/pcre-debuginfo-4.5-3.1.1.fc3.i386.rpm

This update can also be installed with the Update Agent; you can

launch the Update Agent with the 'up2date' command.

fedora-announce-list mailing list

fedora-announce-list@redhat.com

Change Log

References

Update Instructions

Severity
critical
Lowest
Low
Medium
High
Critical

Name: pcre
Version: 4.5
Release: 3.1.1.fc3
Summary: Perl-compatible regular expression library.

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here