An update that fixes two vulnerabilities is now available. . openSUSE Security Update: Security update for pcre ______________________________________________________________________________ Announcement ID: openSUSE-SU-2021:3529-1 Rating: moderate References: #1172973 #1172974 Cross-References: CVE-2019-20838 CVE-2020-14155 CVSS scores: CVE-2019-20838 (NVD) : 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H CVE-2019-20838 (SUSE): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H CVE-2020-14155 (NVD) : 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L CVE-2020-14155 (SUSE): 6.2 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H Affected Products: openSUSE Leap 15.3 ______________________________________________________________________________ An update that fixes two vulnerabilities is now available. Description: This update for pcre fixes the following issues: Update pcre to version 8.45: - CVE-2020-14155: Fixed integer overflow via a large number after a '(?C' substring (bsc#1172974). - CVE-2019-20838: Fixed buffer over-read in JIT compiler (bsc#1172973) Patch Instructions: To install this openSUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - openSUSE Leap 15.3: zypper in -t patch openSUSE-SLE-15.3-2021-3529=1 Package List: - openSUSE Leap 15.3 (aarch64 ppc64le s390x x86_64): libpcre1-8.45-20.10.1 libpcre1-debuginfo-8.45-20.10.1 libpcre16-0-8.45-20.10.1 libpcre16-0-debuginfo-8.45-20.10.1 libpcrecpp0-8.45-20.10.1 libpcrecpp0-debuginfo-8.45-20.10.1 libpcreposix0-8.45-20.10.1 libpcreposix0-debuginfo-8.45-20.10.1 pcre-debugsource-8.45-20.10.1 pcre-devel-8.45-20.10.1 pcre-devel-static-8.45-20.10.1 pcre-tools-8.45-20.10.1 pcre-tools-debuginfo-8.45-20.10.1 - openSUSE Leap 15.3 (noarch): pcre-doc-8.45-20.10.1 - openSUSE Leap 15.3 (x86_64): libpcre1-32bit-8.45-20.10.1 libpcre1-32bit-debuginfo-8.45-20.10.1 libpcre16-0-32bit-8.45-20.10.1 libpcre16-0-32bit-debuginfo-8.45-20.10.1 libpcrecpp0-32bit-8.45-20.10.1 libpcrecpp0-32bit-debuginfo-8.45-20.10.1 libpcreposix0-32bit-8.45-20.10.1 libpcreposix0-32bit-debuginfo-8.45-20.10.1 References: https://www.suse.com/security/cve/CVE-2019-20838.html https://www.suse.com/security/cve/CVE-2020-14155.html https://bugzilla.suse.com/1172973 https://bugzilla.suse.com/1172974 . Updates addressing pcre security issues on openSUSE focus on improving system protection with enhanced package versions ready for installation.. openSUSE Security Update,pcre Update,Threat Mitigation,Software Patch. . LinuxSecurity.com Team
Updated pcre packages fix security vulnerabilities: The pcre package has been updated to version 8.44, fixing an integer overflow and NULL pointer dereference, as well as other bugs. See the upstream changelog for details. . MGASA-2020-0124 - Updated pcre packages fix security vulnerability Publication date: 06 Mar 2020 URL: https://advisories.mageia.org/MGASA-2020-0124.html Type: security Affected Mageia releases: 7 Updated pcre packages fix security vulnerabilities: The pcre package has been updated to version 8.44, fixing an integer overflow and NULL pointer dereference, as well as other bugs. See the upstream changelog for details. References: - https://bugs.mageia.org/show_bug.cgi?id=26274 - SRPMS: - 7/core/pcre-8.44-1.mga7 . Mageia 2020-0125 resolves significant vulnerabilities within pcre by upgrading to version 8.45, which tackles memory corruption and segmentation fault concerns.. Mageia Security Advisory, Integer Overflow Fix, PCRE Package Update. . Severity: Critical. LinuxSecurity.com Team
Important: pcre security update. Date: Thu, 29 Nov 2007 16:24:55 -0600 Reply-To: Troy Dawson Sender: Security Errata for Scientific Linux From: Troy Dawson Subject: Security ERRATA for pcre on SL5.x i386/x86_64 Comments: To: "
Updated pcre packages that correct security issues are now available for Red Hat Enterprise Linux 4 and 5. Flaws were found in the way PCRE handles certain malformed regular expressions. If an application linked against PCRE, such as Konqueror, parses a malicious regular expression, it may be possible to run arbitrary code as the user running the application. This update has been rated as having critical security impact by the Red Hat Security Response Team.. - --------------------------------------------------------------------- Red Hat Security Advisory Synopsis: Critical: pcre security update Advisory ID: RHSA-2007:1052-01 Advisory URL: https://access.redhat.com/errata/RHSA-2007:1052.html Issue date: 2007-11-09 Updated on: 2007-11-09 Product: Red Hat Enterprise Linux CVE Names: CVE-2006-7224 - ---------------------------------------------------------------------1. Summary: Updated pcre packages that correct security issues are now available for Red Hat Enterprise Linux 4 and 5. This update has been rated as having critical security impact by the Red Hat Security Response Team. 2. Relevant releases/architectures: Red Hat Enterprise Linux AS version 4 - i386, ia64, ppc, s390, s390x, x86_64 Red Hat Enterprise Linux Desktop version 4 - i386, x86_64 Red Hat Enterprise Linux ES version 4 - i386, ia64, x86_64 Red Hat Enterprise Linux WS version 4 - i386, ia64, x86_64 Red Hat Enterprise Linux Desktop (v. 5 client) - i386, x86_64 RHEL Desktop Workstation (v. 5 client) - i386, x86_64 Red Hat Enterprise Linux (v. 5 server) - i386, ia64, ppc, s390x, x86_64 3. Problem description: PCRE is a Perl-compatible regular expression library. Flaws were found in the way PCRE handles certain malformed regular expressions. If an application linked against PCRE, such as Konqueror, parses a malicious regular expression, it may be possible to run arbitrary code as the user running the application.(CVE-2006-7224) Users of PCRE are advised to upgrade to these updated packages, which contain a backported patch to correct these issues. 4. Solution: Before applying this update, make sure that all previously-released errata relevant to your system have been applied. This update is available via Red Hat Network. Details on how to use the Red Hat Network to apply this update are available at 5. Bug IDs fixed (http://bugzilla.redhat.com/): 373021 - CVE-2006-7224 pcre multiple integer overflows 6. RPMs required: Red Hat Enterprise Linux AS version 4: SRPMS: 49236e545db29026eea3109c3fdba5ae pcre-4.5-4.el4_5.4.src.rpm i386: 6c4d5d457bdcd8d9d03b1e825077f55e pcre-4.5-4.el4_5.4.i386.rpm f10161895acc6659bb081a51400f6c79 pcre-debuginfo-4.5-4.el4_5.4.i386.rpm db9170f905d681c7b6a0ca283043da41 pcre-devel-4.5-4.el4_5.4.i386.rpm ia64: 6c4d5d457bdcd8d9d03b1e825077f55e pcre-4.5-4.el4_5.4.i386.rpm a9f0e8482a18d5c51a736ddb1c2344b5 pcre-4.5-4.el4_5.4.ia64.rpm f10161895acc6659bb081a51400f6c79 pcre-debuginfo-4.5-4.el4_5.4.i386.rpm 732379892973afb39c50a375849021cc pcre-debuginfo-4.5-4.el4_5.4.ia64.rpm 2027d9e67ac017b59da16034cc89177c pcre-devel-4.5-4.el4_5.4.ia64.rpm ppc: f551684382e6beee3c585a13dd2bf652 pcre-4.5-4.el4_5.4.ppc.rpm ecb064a62fa97b7b29d73dde82e4f7f4 pcre-4.5-4.el4_5.4.ppc64.rpm 158ecbc3d5e51d0fe2c64651200481b2 pcre-debuginfo-4.5-4.el4_5.4.ppc.rpm 3239b9b56d0ee1892635fd6223a4e99a pcre-debuginfo-4.5-4.el4_5.4.ppc64.rpm c24ca5e4617e57414335b82d77867906 pcre-devel-4.5-4.el4_5.4.ppc.rpm s390: 06e9196587cd01b1ff6fb6dc10247f47 pcre-4.5-4.el4_5.4.s390.rpm bc79fe3e2811bf0bf47cc8a36b358cce pcre-debuginfo-4.5-4.el4_5.4.s390.rpm ea0f4ca567fdddd5ef765ea13eefa98f pcre-devel-4.5-4.el4_5.4.s390.rpm s390x: 06e9196587cd01b1ff6fb6dc10247f47 pcre-4.5-4.el4_5.4.s390.rpm 0bc4bab9367aef27216d568059340d43 pcre-4.5-4.el4_5.4.s390x.rpm bc79fe3e2811bf0bf47cc8a36b358cce pcre-debuginfo-4.5-4.el4_5.4.s390.rpm 5cad83935892bb7a0f9b92df7cd6e8e4 pcre-debuginfo-4.5-4.el4_5.4.s390x.rpm 22218623a862c125c4be76ce819d9705 pcre-devel-4.5-4.el4_5.4.s390x.rpm x86_64: 6c4d5d457bdcd8d9d03b1e825077f55e pcre-4.5-4.el4_5.4.i386.rpm 1c9d0bb0a1c176950e0469d92d48748a pcre-4.5-4.el4_5.4.x86_64.rpm f10161895acc6659bb081a51400f6c79 pcre-debuginfo-4.5-4.el4_5.4.i386.rpm c383e03fb1d6a1f561751b03030e6cde pcre-debuginfo-4.5-4.el4_5.4.x86_64.rpm cb6ac02502f662374d4de938aa2e19c4 pcre-devel-4.5-4.el4_5.4.x86_64.rpm Red Hat Enterprise Linux Desktop version 4: SRPMS: 49236e545db29026eea3109c3fdba5ae pcre-4.5-4.el4_5.4.src.rpm i386: 6c4d5d457bdcd8d9d03b1e825077f55e pcre-4.5-4.el4_5.4.i386.rpm f10161895acc6659bb081a51400f6c79 pcre-debuginfo-4.5-4.el4_5.4.i386.rpm db9170f905d681c7b6a0ca283043da41 pcre-devel-4.5-4.el4_5.4.i386.rpm x86_64: 6c4d5d457bdcd8d9d03b1e825077f55e pcre-4.5-4.el4_5.4.i386.rpm 1c9d0bb0a1c176950e0469d92d48748a pcre-4.5-4.el4_5.4.x86_64.rpm f10161895acc6659bb081a51400f6c79 pcre-debuginfo-4.5-4.el4_5.4.i386.rpm c383e03fb1d6a1f561751b03030e6cde pcre-debuginfo-4.5-4.el4_5.4.x86_64.rpm cb6ac02502f662374d4de938aa2e19c4 pcre-devel-4.5-4.el4_5.4.x86_64.rpm Red Hat Enterprise Linux ES version 4: SRPMS: 49236e545db29026eea3109c3fdba5ae pcre-4.5-4.el4_5.4.src.rpm i386: 6c4d5d457bdcd8d9d03b1e825077f55e pcre-4.5-4.el4_5.4.i386.rpm f10161895acc6659bb081a51400f6c79 pcre-debuginfo-4.5-4.el4_5.4.i386.rpm db9170f905d681c7b6a0ca283043da41 pcre-devel-4.5-4.el4_5.4.i386.rpm ia64: 6c4d5d457bdcd8d9d03b1e825077f55e pcre-4.5-4.el4_5.4.i386.rpm a9f0e8482a18d5c51a736ddb1c2344b5 pcre-4.5-4.el4_5.4.ia64.rpm f10161895acc6659bb081a51400f6c79 pcre-debuginfo-4.5-4.el4_5.4.i386.rpm 732379892973afb39c50a375849021cc pcre-debuginfo-4.5-4.el4_5.4.ia64.rpm 2027d9e67ac017b59da16034cc89177c pcre-devel-4.5-4.el4_5.4.ia64.rpm x86_64: 6c4d5d457bdcd8d9d03b1e825077f55e pcre-4.5-4.el4_5.4.i386.rpm 1c9d0bb0a1c176950e0469d92d48748a pcre-4.5-4.el4_5.4.x86_64.rpm f10161895acc6659bb081a51400f6c79 pcre-debuginfo-4.5-4.el4_5.4.i386.rpm c383e03fb1d6a1f561751b03030e6cde pcre-debuginfo-4.5-4.el4_5.4.x86_64.rpm cb6ac02502f662374d4de938aa2e19c4 pcre-devel-4.5-4.el4_5.4.x86_64.rpm Red Hat Enterprise Linux WS version 4: SRPMS: 49236e545db29026eea3109c3fdba5ae pcre-4.5-4.el4_5.4.src.rpm i386: 6c4d5d457bdcd8d9d03b1e825077f55e pcre-4.5-4.el4_5.4.i386.rpm f10161895acc6659bb081a51400f6c79 pcre-debuginfo-4.5-4.el4_5.4.i386.rpm db9170f905d681c7b6a0ca283043da41 pcre-devel-4.5-4.el4_5.4.i386.rpm ia64: 6c4d5d457bdcd8d9d03b1e825077f55e pcre-4.5-4.el4_5.4.i386.rpm a9f0e8482a18d5c51a736ddb1c2344b5 pcre-4.5-4.el4_5.4.ia64.rpm f10161895acc6659bb081a51400f6c79 pcre-debuginfo-4.5-4.el4_5.4.i386.rpm 732379892973afb39c50a375849021cc pcre-debuginfo-4.5-4.el4_5.4.ia64.rpm 2027d9e67ac017b59da16034cc89177c pcre-devel-4.5-4.el4_5.4.ia64.rpm x86_64: 6c4d5d457bdcd8d9d03b1e825077f55e pcre-4.5-4.el4_5.4.i386.rpm 1c9d0bb0a1c176950e0469d92d48748a pcre-4.5-4.el4_5.4.x86_64.rpm f10161895acc6659bb081a51400f6c79 pcre-debuginfo-4.5-4.el4_5.4.i386.rpm c383e03fb1d6a1f561751b03030e6cde pcre-debuginfo-4.5-4.el4_5.4.x86_64.rpm cb6ac02502f662374d4de938aa2e19c4 pcre-devel-4.5-4.el4_5.4.x86_64.rpm Red Hat Enterprise Linux Desktop (v. 5 client): SRPMS: 230040f3f36e5664ce5a6671334f6ddb pcre-6.6-2.el5_1.1.src.rpm i386: 0bedc083211d95e89d11fbbddc07e968 pcre-6.6-2.el5_1.1.i386.rpm 57892457eef33e35b1fc5528a42bcd94 pcre-debuginfo-6.6-2.el5_1.1.i386.rpm x86_64: 0bedc083211d95e89d11fbbddc07e968 pcre-6.6-2.el5_1.1.i386.rpm 6ce8eee6c331ca63a39e0fe03c7fb985 pcre-6.6-2.el5_1.1.x86_64.rpm 57892457eef33e35b1fc5528a42bcd94 pcre-debuginfo-6.6-2.el5_1.1.i386.rpm 1cac5a613d8b28267e8db6f7cb2afd46 pcre-debuginfo-6.6-2.el5_1.1.x86_64.rpm RHEL Desktop Workstation (v. 5 client): SRPMS: 230040f3f36e5664ce5a6671334f6ddb pcre-6.6-2.el5_1.1.src.rpm i386: 57892457eef33e35b1fc5528a42bcd94 pcre-debuginfo-6.6-2.el5_1.1.i386.rpm c53d0803d49bf739b59539eb5782f43f pcre-devel-6.6-2.el5_1.1.i386.rpm x86_64: 57892457eef33e35b1fc5528a42bcd94 pcre-debuginfo-6.6-2.el5_1.1.i386.rpm 1cac5a613d8b28267e8db6f7cb2afd46 pcre-debuginfo-6.6-2.el5_1.1.x86_64.rpm c53d0803d49bf739b59539eb5782f43f pcre-devel-6.6-2.el5_1.1.i386.rpm cc64b53c0d0b0d4fac6429baad17fba2 pcre-devel-6.6-2.el5_1.1.x86_64.rpm Red Hat Enterprise Linux (v. 5 server): SRPMS: 230040f3f36e5664ce5a6671334f6ddb pcre-6.6-2.el5_1.1.src.rpm i386: 0bedc083211d95e89d11fbbddc07e968 pcre-6.6-2.el5_1.1.i386.rpm 57892457eef33e35b1fc5528a42bcd94 pcre-debuginfo-6.6-2.el5_1.1.i386.rpm c53d0803d49bf739b59539eb5782f43f pcre-devel-6.6-2.el5_1.1.i386.rpm ia64: b7ef7d4d91f0425011c348e81140a5f3 pcre-6.6-2.el5_1.1.ia64.rpm 888ea998576acca5a6a8529c2da64f87 pcre-debuginfo-6.6-2.el5_1.1.ia64.rpm a424e60ea30261a2650124df2fe0b914 pcre-devel-6.6-2.el5_1.1.ia64.rpm ppc: 8f903834f10271879e1a08d87987cad1 pcre-6.6-2.el5_1.1.ppc.rpm cea8361d9d14c7fae8a57274ea02b33b pcre-6.6-2.el5_1.1.ppc64.rpm ffec123b0c84c123042501d9511030b5 pcre-debuginfo-6.6-2.el5_1.1.ppc.rpm 30e0adc7d5a7798dec12dbb04cd15e31 pcre-debuginfo-6.6-2.el5_1.1.ppc64.rpm 3423c3eb767d485eb26e6808b2204cf1 pcre-devel-6.6-2.el5_1.1.ppc.rpm d7b38446e64240c6d8e442552e9f5dbb pcre-devel-6.6-2.el5_1.1.ppc64.rpm s390x: b06798c560af2b94f7e7b6448cdeefac pcre-6.6-2.el5_1.1.s390.rpm bf9ec28737e79e899638a08b74f3fbf5 pcre-6.6-2.el5_1.1.s390x.rpm 3e4d44a6ed3dea1629280c91000ff5a5 pcre-debuginfo-6.6-2.el5_1.1.s390.rpm 5e3fef773f0a841bf5c4b2c448a52327 pcre-debuginfo-6.6-2.el5_1.1.s390x.rpm ca23b3b464e301f25229e9d5fd654909 pcre-devel-6.6-2.el5_1.1.s390.rpm bb72d6e9246bbe645dcb9eecef9d6fe6 pcre-devel-6.6-2.el5_1.1.s390x.rpm x86_64: 0bedc083211d95e89d11fbbddc07e968 pcre-6.6-2.el5_1.1.i386.rpm 6ce8eee6c331ca63a39e0fe03c7fb985 pcre-6.6-2.el5_1.1.x86_64.rpm 57892457eef33e35b1fc5528a42bcd94 pcre-debuginfo-6.6-2.el5_1.1.i386.rpm 1cac5a613d8b28267e8db6f7cb2afd46 pcre-debuginfo-6.6-2.el5_1.1.x86_64.rpm c53d0803d49bf739b59539eb5782f43f pcre-devel-6.6-2.el5_1.1.i386.rpm cc64b53c0d0b0d4fac6429baad17fba2 pcre-devel-6.6-2.el5_1.1.x86_64.rpm These packages are GPG signed by Red Hat for security. Our key and details on how to verify the signature are available from https://access.redhat.com/security/team/key#package 7. References: https://www.cve.org/CVERecord?id=CVE-2006-7224 https://access.redhat.com/security/updates/classification#critical 8. Contact: The Red Hat security contact is . More contact details at https://access.redhat.com/security/team/contact Copyright 2007 Red Hat, Inc. . Red Hat has issued an urgent security patch for PCRE as vulnerabilities could enable possible code execution.. PCRE Security Update, Red Hat Advisory, Critical Patch. . Severity: Critical. LinuxSecurity.com Team
Moderate: pcre security update. Date: Fri, 16 Sep 2005 17:30:16 -0500 Reply-To: Connie Sieh Sender: Security Errata for Scientific Linux From: Connie Sieh Subject: ERRATA for SL 302,305 ia64 now available Comments: To:
Moderate: pcre security update. Date: Thu, 8 Sep 2005 16:20:38 -0500 Reply-To: Troy Dawson Sender: Security Errata for Scientific Linux From: Troy Dawson Subject: ERRATA for SL 40,41 i386 now available Comments: To:
Moderate: pcre security update. Date: Thu, 8 Sep 2005 16:20:00 -0500 Reply-To: Troy Dawson Sender: Security Errata for Scientific Linux From: Troy Dawson Subject: ERRATA for SL 40,41 x86_64 now available Comments: To:
New PCRE packages are available for Slackware 8.1, 9.0, 9.1, 10.0, 10.1, and -current to fix a security issue. A buffer overflow could be triggered by a specially crafted regular expression. Any applications that use PCRE to process untrusted regular expressions may be exploited to run arbitrary . -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 [slackware-security] PCRE library (SSA:2005-242-01) New PCRE packages are available for Slackware 8.1, 9.0, 9.1, 10.0, 10.1, and -current to fix a security issue. A buffer overflow could be triggered by a specially crafted regular expression. Any applications that use PCRE to process untrusted regular expressions may be exploited to run arbitrary code as the user running the application. The PCRE library is also provided in an initial installation by the aaa_elflibs package, so if your system has a /usr/lib/libpcre.so.0 symlink, then you should install this updated package even if the PCRE package itself is not installed on the system. More details about this issue may be found in the Common Vulnerabilities and Exposures (CVE) database: https://www.cve.org/CVERecord?id=CAN-2005-2491 Here are the details from the Slackware 10.1 ChangeLog: +--------------------------+ patches/packages/pcre-6.3-i486-1.tgz: Upgraded to pcre-6.3. This fixes a buffer overflow that could be triggered by the processing of a specially crafted regular expression. Theoretically this could be a security issue if regular expressions are accepted from untrusted users to be processed by a user with greater privileges, but this doesn't seem like a common scenario (or, for that matter, a good idea). However, if you are using an application that links to the shared PCRE library and accepts outside input in such a manner, you will want to update to this new package. For more information, see: https://www.cve.org/CVERecord?id=CAN-2005-2491 (* Security fix *) +--------------------------+ Where to find the new packages: +-----------------------------+ Updated package forSlackware 8.1: ftp://ftp.slackware.com/pub/slackware/slackware-8.1/patches/packages/pcre-6.3-i386-1.tgz Updated package for Slackware 9.0: ftp://ftp.slackware.com/pub/slackware/slackware-9.0/patches/packages/pcre-6.3-i386-1.tgz Updated package for Slackware 9.1: ftp://ftp.slackware.com/pub/slackware/slackware-9.1/patches/packages/pcre-6.3-i486-1.tgz Updated package for Slackware 10.0: ftp://ftp.slackware.com/pub/slackware/slackware-10.0/patches/packages/pcre-6.3-i486-1.tgz Updated package for Slackware 10.1: ftp://ftp.slackware.com/pub/slackware/slackware-10.1/patches/packages/pcre-6.3-i486-1.tgz Updated package for Slackware -current: MD5 signatures: +-------------+ Slackware 8.1 package: 6d4ea9a84341297ebb86a3d218ee6520 pcre-6.3-i386-1.tgz Slackware 9.0 package: 539769e82bb6e03db449f4154d557e36 pcre-6.3-i386-1.tgz Slackware 9.1 package: bb49c4be6ba9c8ed19d4be7997da065a pcre-6.3-i486-1.tgz Slackware 10.0 package: 591c6fce5c0084f668bab1ea3ada4ebe pcre-6.3-i486-1.tgz Slackware 10.1 package: 8f5f604fd35876d397d4e2d4e4fe83a1 pcre-6.3-i486-1.tgz Slackware -current package: c699044b38a70720439ace1097e84013 pcre-6.3-i486-1.tgz Installation instructions: +------------------------+ Upgrade the package as root: # upgradepkg pcre-6.3-i486-1.tgz Then, restart any applications that use the PCRE library. +-----+ . Updated PCRE modules address security vulnerabilities in Slackware 8.1 - now implemented to safeguard systems against possible threats.. PCRE Security Update, Slackware Package Update, Buffer Overflow Fix. . Severity: Critical. LinuxSecurity.com Team
Get the latest Linux and open source security news straight to your inbox.