- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
Gentoo Linux Security Advisory                           GLSA 201607-02
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
                                           https://security.gentoo.org/
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -

 Severity: Normal
    Title: libpcre: Multiple Vulnerabilities
     Date: July 09, 2016
     Bugs: #529952, #551240, #553300, #570694, #575546
       ID: 201607-02

- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -

Synopsis
=======
Multiple vulnerabilities have been found in libpcre, the worst of which
could lead to arbitrary code execution, or cause a Denial of Service
condition.

Background
=========
libpcre is a library providing functions for Perl-compatible regular
expressions.

Affected packages
================
    -------------------------------------------------------------------
     Package              /     Vulnerable     /            Unaffected
    -------------------------------------------------------------------
  1  dev-libs/libpcre            < 8.38-r1                 >= 8.38-r1 

Description
==========
Multiple vulnerabilities have been discovered in libpcre. Please review
the CVE identifiers referenced below for details.

Impact
=====
An attacker can possibly execute arbitrary code or create a Denial of
Service condition.

Workaround
=========
There is no known workaround at this time.

Resolution
=========
All libpcre users should upgrade to the latest version:

  # emerge --sync
  # emerge --ask --oneshot --verbose ">=dev-libs/libpcre-8.38-r1"

References
=========
[  1 ] CVE-2014-8964
       http://nvd.nist.gov/nvd.cfm?cvename=CVE-2014-8964
[  2 ] CVE-2014-8964
       http://nvd.nist.gov/nvd.cfm?cvename=CVE-2014-8964
[  3 ] CVE-2015-5073
       http://nvd.nist.gov/nvd.cfm?cvename=CVE-2015-5073
[  4 ] CVE-2015-5073
       http://nvd.nist.gov/nvd.cfm?cvename=CVE-2015-5073
[  5 ] CVE-2015-5073
       http://nvd.nist.gov/nvd.cfm?cvename=CVE-2015-5073
[  6 ] CVE-2015-8380
       http://nvd.nist.gov/nvd.cfm?cvename=CVE-2015-8380
[  7 ] CVE-2015-8381
       http://nvd.nist.gov/nvd.cfm?cvename=CVE-2015-8381
[  8 ] CVE-2015-8383
       http://nvd.nist.gov/nvd.cfm?cvename=CVE-2015-8383
[  9 ] CVE-2015-8384
       http://nvd.nist.gov/nvd.cfm?cvename=CVE-2015-8384
[ 10 ] CVE-2015-8385
       http://nvd.nist.gov/nvd.cfm?cvename=CVE-2015-8385
[ 11 ] CVE-2015-8386
       http://nvd.nist.gov/nvd.cfm?cvename=CVE-2015-8386
[ 12 ] CVE-2015-8387
       http://nvd.nist.gov/nvd.cfm?cvename=CVE-2015-8387
[ 13 ] CVE-2015-8388
       http://nvd.nist.gov/nvd.cfm?cvename=CVE-2015-8388
[ 14 ] CVE-2015-8389
       http://nvd.nist.gov/nvd.cfm?cvename=CVE-2015-8389
[ 15 ] CVE-2015-8390
       http://nvd.nist.gov/nvd.cfm?cvename=CVE-2015-8390
[ 16 ] CVE-2015-8391
       http://nvd.nist.gov/nvd.cfm?cvename=CVE-2015-8391
[ 17 ] CVE-2015-8392
       http://nvd.nist.gov/nvd.cfm?cvename=CVE-2015-8392
[ 18 ] CVE-2015-8393
       http://nvd.nist.gov/nvd.cfm?cvename=CVE-2015-8393
[ 19 ] CVE-2015-8394
       http://nvd.nist.gov/nvd.cfm?cvename=CVE-2015-8394
[ 20 ] CVE-2015-8395
       http://nvd.nist.gov/nvd.cfm?cvename=CVE-2015-8395
[ 21 ] CVE-2016-1283
       http://nvd.nist.gov/nvd.cfm?cvename=CVE-2016-1283
[ 22 ] CVE-2016-1283
       http://nvd.nist.gov/nvd.cfm?cvename=CVE-2016-1283

Availability
===========
This GLSA and any updates to it are available for viewing at
the Gentoo Security Website:

 https://security.gentoo.org/glsa/201607-02

Concerns?
========
Security is a primary focus of Gentoo Linux and ensuring the
confidentiality and security of our users' machines is of utmost
importance to us. Any security concerns should be addressed to
security@gentoo.org or alternatively, you may file a bug at
https://bugs.gentoo.org.

License
======
Copyright 2016 Gentoo Foundation, Inc; referenced text
belongs to its owner(s).

The contents of this document are licensed under the
Creative Commons - Attribution / Share Alike license.

https://creativecommons.org/licenses/by-sa/2.5/

Gentoo: GLSA-201607-02: libpcre: Multiple Vulnerabilities

Multiple vulnerabilities have been found in libpcre, the worst of which could lead to arbitrary code execution, or cause a Denial of Service condition

Summary

Multiple vulnerabilities have been discovered in libpcre. Please review the CVE identifiers referenced below for details.

Resolution

All libpcre users should upgrade to the latest version: # emerge --sync # emerge --ask --oneshot --verbose ">=dev-libs/libpcre-8.38-r1"

References

[ 1 ] CVE-2014-8964 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2014-8964 [ 2 ] CVE-2014-8964 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2014-8964 [ 3 ] CVE-2015-5073 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2015-5073 [ 4 ] CVE-2015-5073 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2015-5073 [ 5 ] CVE-2015-5073 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2015-5073 [ 6 ] CVE-2015-8380 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2015-8380 [ 7 ] CVE-2015-8381 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2015-8381 [ 8 ] CVE-2015-8383 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2015-8383 [ 9 ] CVE-2015-8384 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2015-8384 [ 10 ] CVE-2015-8385 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2015-8385 [ 11 ] CVE-2015-8386 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2015-8386 [ 12 ] CVE-2015-8387 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2015-8387 [ 13 ] CVE-2015-8388 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2015-8388 [ 14 ] CVE-2015-8389 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2015-8389 [ 15 ] CVE-2015-8390 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2015-8390 [ 16 ] CVE-2015-8391 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2015-8391 [ 17 ] CVE-2015-8392 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2015-8392 [ 18 ] CVE-2015-8393 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2015-8393 [ 19 ] CVE-2015-8394 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2015-8394 [ 20 ] CVE-2015-8395 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2015-8395 [ 21 ] CVE-2016-1283 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2016-1283 [ 22 ] CVE-2016-1283 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2016-1283

Availability

This GLSA and any updates to it are available for viewing at the Gentoo Security Website: https://security.gentoo.org/glsa/201607-02

Concerns

Security is a primary focus of Gentoo Linux and ensuring the confidentiality and security of our users' machines is of utmost importance to us. Any security concerns should be addressed to security@gentoo.org or alternatively, you may file a bug at https://bugs.gentoo.org.

Severity
Severity: Normal
Title: libpcre: Multiple Vulnerabilities
Date: July 09, 2016
Bugs: #529952, #551240, #553300, #570694, #575546
ID: 201607-02

Synopsis

Multiple vulnerabilities have been found in libpcre, the worst of which could lead to arbitrary code execution, or cause a Denial of Service condition.

Background

libpcre is a library providing functions for Perl-compatible regular expressions.

Affected Packages

------------------------------------------------------------------- Package / Vulnerable / Unaffected ------------------------------------------------------------------- 1 dev-libs/libpcre < 8.38-r1 >= 8.38-r1

Impact

===== An attacker can possibly execute arbitrary code or create a Denial of Service condition.

Workaround

There is no known workaround at this time.

Related News