PT-2005-5569 · Pcre+1 · Libpcre3-Dev+9

Tavis Ormandy

·

Publicado

1970-01-01

·

Atualizado

2018-10-16

·

CVE-2007-1659

CVSS v2.0

7.5

Alta

VetorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions libpcrecpp0 versions (affected versions not specified) libpcre3 versions (affected versions not specified) libpcre versions prior to 7.3-r1 pcre-32bit versions (affected versions not specified) pcregrep versions (affected versions not specified) pcre versions (affected versions not specified) libpcre3-dev versions (affected versions not specified) pgrep versions (affected versions not specified) pcre-devel versions (affected versions not specified)
Description The issue concerns multiple vulnerabilities in the PCRE library, which can lead to disruption of confidentiality, integrity, and availability of protected information. These vulnerabilities can be exploited remotely. The vulnerabilities allow context-dependent attackers to cause a denial of service and possibly execute arbitrary code via regex patterns containing unmatched "QE" sequences with orphan "E" codes.
Recommendations For libpcrecpp0, update to a version that contains a fix for this issue. For libpcre3, update to a version that contains a fix for this issue. For libpcre, update to version 7.3-r1 or later. For pcre-32bit, update to a version that contains a fix for this issue. For pcregrep, update to a version that contains a fix for this issue. For pcre, update to a version that contains a fix for this issue. For libpcre3-dev, update to a version that contains a fix for this issue. For pgrep, update to a version that contains a fix for this issue. For pcre-devel, update to a version that contains a fix for this issue.

Correção

DoS

Buffer Overflow

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2015-02588
BDU:2015-02589
BDU:2015-02590
BDU:2015-02591
BDU:2015-03061
BDU:2015-04723
BDU:2015-04724
BDU:2015-04725
BDU:2015-09569
CVE-2007-1659
DSA-1399-1
DSA-1570-1
DTSA-77-1
RHSA-2007:0967
RHSA-2007:1068
RHSA-2007_0967
RHSA-2007_1068

Produtos afetados

Red Hat
Libpcre
Libpcre3
Libpcre3-Dev
Libpcrecpp0
Pcre
Pcre-32Bit
Pcre-Devel
Pcregrep
Pgrep