The container suse/sles12sp5 was updated. The following patches have been included in this update:. SUSE Container Update Advisory: suse/sles12sp5 ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2022:1534-1 Container Tags : suse/sles12sp5:6.5.349 , suse/sles12sp5:latest Container Release : 6.5.349 Severity : important Type : security References : 1199232 CVE-2022-1586 ----------------------------------------------------------------- The container suse/sles12sp5 was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2022:2334-1 Released: Fri Jul 8 10:12:23 2022 Summary: Security update for pcre Type: security Severity: important References: 1199232,CVE-2022-1586 This update for pcre fixes the following issues: - CVE-2022-1586: Fixed unicode property matching issue. (bsc#1199232) The following package changes have been done: - libpcre1-8.45-8.12.1 updated . SUSE Container suse/sles12sp5 has been updated to address security vulnerabilities; it includes essential updates for libpcre1.. SUSE Container, suse/sles12sp5, security fix, libpcre1 update. . Severity: Important. LinuxSecurity.com Team
Multiple vulnerabilities have been found in libpcre, the worst of which could lead to arbitrary code execution, or cause a Denial of Service condition. [More...]. - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Gentoo Linux Security Advisory GLSA 201607-02 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - https://security.gentoo.org/ - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Severity: Normal Title: libpcre: Multiple Vulnerabilities Date: July 09, 2016 Bugs: #529952, #551240, #553300, #570694, #575546 ID: 201607-02 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Synopsis ======= Multiple vulnerabilities have been found in libpcre, the worst of which could lead to arbitrary code execution, or cause a Denial of Service condition. Background ========= libpcre is a library providing functions for Perl-compatible regular expressions. Affected packages ================ ------------------------------------------------------------------- Package / Vulnerable / Unaffected ------------------------------------------------------------------- 1 dev-libs/libpcre < 8.38-r1 > = 8.38-r1 Description ========== Multiple vulnerabilities have been discovered in libpcre. Please review the CVE identifiers referenced below for details. Impact ===== An attacker can possibly execute arbitrary code or create a Denial of Service condition. Workaround ========= There is no known workaround at this time. Resolution ========= All libpcre users should upgrade to the latest version: # emerge --sync # emerge --ask --oneshot --verbose "> =dev-libs/libpcre-8.38-r1" References ========= [ 1 ] CVE-2014-8964 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2014-8964 [ 2 ] CVE-2014-8964 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2014-8964 [ 3 ] CVE-2015-5073 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2015-5073 [ 4 ] CVE-2015-5073 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2015-5073 [ 5 ] CVE-2015-5073 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2015-5073 [ 6 ] CVE-2015-8380 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2015-8380 [ 7 ] CVE-2015-8381 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2015-8381 [ 8 ] CVE-2015-8383 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2015-8383 [ 9 ] CVE-2015-8384 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2015-8384 [ 10 ] CVE-2015-8385 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2015-8385 [ 11 ] CVE-2015-8386 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2015-8386 [ 12 ] CVE-2015-8387 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2015-8387 [ 13 ] CVE-2015-8388 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2015-8388 [ 14 ] CVE-2015-8389 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2015-8389 [ 15 ] CVE-2015-8390 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2015-8390 [ 16 ] CVE-2015-8391 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2015-8391 [ 17 ] CVE-2015-8392 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2015-8392 [ 18 ] CVE-2015-8393 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2015-8393 [ 19 ] CVE-2015-8394 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2015-8394 [ 20 ] CVE-2015-8395 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2015-8395 [ 21 ] CVE-2016-1283 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2016-1283 [ 22 ] CVE-2016-1283 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2016-1283 Availability =========== This GLSA and any updates to it are available for viewing at the Gentoo Security Website: https://security.gentoo.org/glsa/201607-02 Concerns? ======== Security is a primary focus of Gentoo Linux and ensuring the confidentiality and security of our users' machines is of utmost importance to us. Any security concerns should be addressed to
libpcre is vulnerable to a heap integer overflow, possibly leading to the execution of arbitrary code.. - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Gentoo Linux Security Advisory GLSA 200508-17 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - https://security.gentoo.org/ - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Severity: High Title: libpcre: Heap integer overflow Date: August 25, 2005 Bugs: #103337 ID: 200508-17 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Synopsis ======= libpcre is vulnerable to a heap integer overflow, possibly leading to the execution of arbitrary code. Background ========= libpcre is a library providing functions for Perl-compatible regular expressions. Affected packages ================ ------------------------------------------------------------------- Package / Vulnerable / Unaffected ------------------------------------------------------------------- 1 dev-libs/libpcre < 6.3 > = 6.3 Description ========== libpcre fails to check certain quantifier values in regular expressions for sane values. Impact ===== An attacker could possibly exploit this vulnerability to execute arbitrary code by sending specially crafted regular expressions to applications making use of the libpcre library. Workaround ========= There is no known workaround at this time. Resolution ========= All libpcre users should upgrade to the latest version: # emerge --sync # emerge --ask --oneshot --verbose "> =dev-libs/libpcre-6.3" References ========= [ 1 ] CAN-2005-2491 https://www.cve.org/CVERecord?id=CAN-2005-2491 [ 2 ] SecurityTracker Alert ID 1014744 Availability =========== This GLSA and any updates to it are available for viewing at the Gentoo Security Website: https://security.gentoo.org/glsa/200508-17 Concerns? ======== Security is a primary focus of Gentoo Linux and ensuring the confidentiality and security of our users machines is of utmost importance to us. Any security concerns should be addressed to
Get the latest Linux and open source security news straight to your inbox.