Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 524
Alerts This Week
Warning Icon 1 524

Red Hat Enterprise Linux 7: RHSA-2015:2111-07 Low: grep Buffer Overflow

red hat
Calendar Grey November 19, 2015
Scroller Redhat
The latest update for grep on Red Hat Enterprise Linux 7 addresses a minor severity buffer overflow issue along with various bug fixes.
Updated grep packages that fix one security issue and several bugs are now available for Red Hat Enterprise Linux 7

Solution

Before applying this update, make sure all previously released errata relevant to your system have been applied.

For details on how to apply this update, refer to:

https://access.redhat.com/articles/11258

Summary

The grep utility searches through textual input for lines that contain a match to a specified pattern and then prints the matching lines. The GNU grep utilities include grep, egrep, and fgrep.
A heap-based buffer overflow flaw was found in the way grep processed certain pattern and text combinations. An attacker able to trick a user into running grep on specially crafted input could use this flaw to crash grep or, potentially, read from uninitialized memory. (CVE-2015-1345)
This update also fixes the following bugs:
* Prior to this update, the w and W symbols were inconsistently matched to the [:alnum:] character class. Consequently, using regular expressions with "w" and "W" could lead to incorrect results. With this update, "w" is consistently matched to the [_[:alnum:]] character, and "W" is consistently matched to the [^_[:alnum:]] character. (BZ#1159012)
* Previously, the Perl Compatible Regular Expression (PCRE) matcher (selected by the "-P" parameter in grep) did not work correctly when matching non-UTF-8 text in UTF-8 locales. Consequently, an error message about invalid UTF-8 byte sequence characters was returned. To fix this bug, patches from upstream have been applied to the grep utility. As a result, PCRE now skips non-UTF-8 characters as non-matching text without returning any error message. (BZ#1217080)
All grep users are advised to upgrade to these updated packages, which contain backported patches to correct these issues.

References

https://access.redhat.com/security/cve/CVE-2015-1345 https://access.redhat.com/security/updates/classification/#low

Package List

Red Hat Enterprise Linux Client (v. 7):
Source: grep-2.20-2.el7.src.rpm
x86_64: grep-2.20-2.el7.x86_64.rpm grep-debuginfo-2.20-2.el7.x86_64.rpm
Red Hat Enterprise Linux ComputeNode (v. 7):
Source: grep-2.20-2.el7.src.rpm
x86_64: grep-2.20-2.el7.x86_64.rpm grep-debuginfo-2.20-2.el7.x86_64.rpm
Red Hat Enterprise Linux Server (v. 7):
Source: grep-2.20-2.el7.src.rpm
aarch64: grep-2.20-2.el7.aarch64.rpm grep-debuginfo-2.20-2.el7.aarch64.rpm
ppc64: grep-2.20-2.el7.ppc64.rpm grep-debuginfo-2.20-2.el7.ppc64.rpm
ppc64le: grep-2.20-2.el7.ppc64le.rpm grep-debuginfo-2.20-2.el7.ppc64le.rpm
s390x: grep-2.20-2.el7.s390x.rpm grep-debuginfo-2.20-2.el7.s390x.rpm
x86_64: grep-2.20-2.el7.x86_64.rpm grep-debuginfo-2.20-2.el7.x86_64.rpm
Red Hat Enterprise Linux Workstation (v. 7):
Source: grep-2.20-2.el7.src.rpm
x86_64: grep-2.20-2.el7.x86_64.rpm grep-debuginfo-2.20-2.el7.x86_64.rpm
These packages are GPG signed by Red Hat for security. Our key and details on how to verify the signature are available from https://access.redhat.com/security/team/key/


Severity
low
Lowest
Low
Medium
High
Critical

Advisory ID: RHSA-2015:2111-07
Product: Red Hat Enterprise Linux
Issue date: 2015-11-19

Topic

Updated grep packages that fix one security issue and several bugs are nowavailable for Red Hat Enterprise Linux 7.Red Hat Product Security has rated this update as having Low securityimpact. A Common Vulnerability Scoring System (CVSS) base score, whichgives a detailed severity rating, is available from the CVE link in theReferences section.

Relevant Releases Architectures

Red Hat Enterprise Linux Client (v. 7) - x86_64

Red Hat Enterprise Linux ComputeNode (v. 7) - x86_64

Red Hat Enterprise Linux Server (v. 7) - aarch64, ppc64, ppc64le, s390x, x86_64

Red Hat Enterprise Linux Workstation (v. 7) - x86_64

Bugs Fixed

1103259 - undocumented option --fixed-regexp

1159012 - inconsistent w and [[:alnum:]] behaviour

1183651 - CVE-2015-1345 grep: heap buffer overrun

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.