Alerts This Week
Warning Icon 1 646
Alerts This Week
Warning Icon 1 646

Ubuntu 15.10 USN-2943-1 Moderate: PCRE Denial of Service

Ubuntu Large Esm H500
PCRE could be made to crash or run programs if it processed a specially-crafted regular expression.
=========================================================================Ubuntu Security Notice USN-2943-1
March 29, 2016

pcre3 vulnerabilities
=========================================================================
A security issue affects these releases of Ubuntu and its derivatives:

- Ubuntu 15.10
- Ubuntu 14.04 LTS
- Ubuntu 12.04 LTS

Summary:

PCRE could be made to crash or run programs if it processed a
specially-crafted regular expression.

Software Description:
- pcre3: Perl 5 Compatible Regular Expression Library

Details:

It was discovered that PCRE incorrectly handled certain regular
expressions. A remote attacker could use this issue to cause applications
using PCRE to crash, resulting in a denial of service, or possibly execute
arbitrary code.

Update instructions:

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 15.10:
  libpcre3                        2:8.35-7.1ubuntu1.3

Ubuntu 14.04 LTS:
  libpcre3                        1:8.31-2ubuntu2.2

Ubuntu 12.04 LTS:
  libpcre3                        8.12-4ubuntu0.2

After a standard system update you need to restart applications using PCRE,
such as the Apache HTTP server and Nginx, to make all the necessary
changes.

References:
  https://ubuntu.com/security/notices/USN-2943-1
  CVE-2014-9769, CVE-2015-2325, CVE-2015-2326, CVE-2015-2327,
  CVE-2015-2328, CVE-2015-3210, CVE-2015-5073, CVE-2015-8380,
  CVE-2015-8381, CVE-2015-8382, CVE-2015-8383, CVE-2015-8384,
  CVE-2015-8385, CVE-2015-8386, CVE-2015-8387, CVE-2015-8388,
  CVE-2015-8389, CVE-2015-8390, CVE-2015-8391, CVE-2015-8392,
  CVE-2015-8393, CVE-2015-8394, CVE-2015-8395, CVE-2016-1283,
  CVE-2016-3191

Package Information:
  https://launchpad.net/ubuntu/+source/pcre3/2:8.35-7.1ubuntu1.3
  https://launchpad.net/ubuntu/+source/pcre3/1:8.31-2ubuntu2.2
  https://launchpad.net/ubuntu/+source/pcre3/8.12-4ubuntu0.2


Ubuntu 15.10 USN-2943-1 Moderate: PCRE Denial of Service

ubuntu
Calendar Grey March 29, 2016
Dist Ubuntu Esm H88
Exploiting PCRE weaknesses can lead to application failures or the running of malicious code on Ubuntu. Ensure systems are upgraded to uphold safety.
PCRE could be made to crash or run programs if it processed a specially-crafted regular expression.

Summary

Update Instructions

The problem can be corrected by updating your system to the following package versions: Ubuntu 15.10: libpcre3 2:8.35-7.1ubuntu1.3 Ubuntu 14.04 LTS: libpcre3 1:8.31-2ubuntu2.2 Ubuntu 12.04 LTS: libpcre3 8.12-4ubuntu0.2 After a standard system update you need to restart applications using PCRE, such as the Apache HTTP server and Nginx, to make all the necessary changes.

References

https://ubuntu.com/security/notices/USN-2943-1

CVE-2014-9769, CVE-2015-2325, CVE-2015-2326, CVE-2015-2327,

CVE-2015-2328, CVE-2015-3210, CVE-2015-5073, CVE-2015-8380,

CVE-2015-8381, CVE-2015-8382, CVE-2015-8383, CVE-2015-8384,

CVE-2015-8385, CVE-2015-8386, CVE-2015-8387, CVE-2015-8388,

CVE-2015-8389, CVE-2015-8390, CVE-2015-8391, CVE-2015-8392,

CVE-2015-8393, CVE-2015-8394, CVE-2015-8395, CVE-2016-1283,

CVE-2016-3191

March 29, 2016

Package Information

https://launchpad.net/ubuntu/+source/pcre3/2:8.35-7.1ubuntu1.3 https://launchpad.net/ubuntu/+source/pcre3/1:8.31-2ubuntu2.2 https://launchpad.net/ubuntu/+source/pcre3/8.12-4ubuntu0.2

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here