|
|
Log in / Subscribe / Register

Mageia alert MGASA-2016-0204 (pcre)

From:  Mageia Updates <buildsystem-daemon@mageia.org>
To:  updates-announce@ml.mageia.org
Subject:  [updates-announce] MGASA-2016-0204: Updated pcre packages fix security vulnerabilities
Date:  Tue, 24 May 2016 00:01:25 +0200
Message-ID:  <20160523220125.5E0B49F751@duvel.mageia.org>

MGASA-2016-0204 - Updated pcre packages fix security vulnerabilities Publication date: 23 May 2016 URL: http://advisories.mageia.org/MGASA-2016-0204.html Type: security Affected Mageia releases: 5 CVE: CVE-2016-1283, CVE-2016-3191 Description: Updated pcre packages fix security vulnerabilities: The pcre_compile2 function in pcre_compile.c in PCRE 8.38 mishandles a paricular pattern and related patterns with named subgroups, which allows remote attackers to cause a denial of service (heap-based buffer overflow) or possibly have unspecified other impact via a crafted regular expression (CVE-2016-1283). The compile_branch function in pcre_compile.c in PCRE 8.x before 8.39 mishandles patterns containing an (*ACCEPT) substring in conjunction with nested parentheses, which allows remote attackers to execute arbitrary code or cause a denial of service (stack-based buffer overflow) via a crafted regular expression (CVE-2016-3191). The pcre package has been updated to the latest CVS as of May 21, 2016, aka 8.39-RC1, which fixes these issues, as well as several other bugs, and possible security issues. References: - https://bugs.mageia.org/show_bug.cgi?id=17438 - http://vcs.pcre.org/pcre/code/trunk/ChangeLog?revision=16... - http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-1283 - http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-3191 SRPMS: - 5/core/pcre-8.38-1.mga5


to post comments


Copyright © 2026, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds